Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows 7 64 Bit Lenovo repair loop


  • Please log in to reply

#1
monkeyboyvin

monkeyboyvin

    Member

  • Member
  • PipPip
  • 11 posts
Recently I turned on my computer to see a black screen, I originally assumed it was just my laptop taking its time to load until 20 minutes passed. I realised something was wrong so I restarted, causing my computer to go into repair mode, unfortunately that too was corrupted. I later attempted to use a windows 7 repair cd that was booted from usb as my laptop does not have a optical drive. A few attempts were made to repair and use command prompt to fix the boot, but it only got me no where except fix the issue with lenovo's repair boot.

At the moment I am stuck with a lenovo laptop which continues to cycle through repair ( which does no help ). I have attempted to boot using other options using F8 with no success. I know that my hdd has not failed because i am able to view the files using an external hdd case. I tried backing up the important files from the hdd although the access was denied :( .

So now I am seeking help to fix the boot of my windows 7. I have read from other threads to use a usb to boot the windows 7 repair cd and use command prompt to use FRST64.exe . I then recognised that I require an actual person to go through the list that FRST64.EXE makes in order to provide a fix list.

I dont want to purchase a new hdd+operating system to revive my laptop.
  • 0

Advertisements


#2
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
:welcome:

Post the FRST64 report.
  • 0

#3
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2013
Ran by SYSTEM at 16-03-2013 08:08:35
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2731304 2011-03-24] (Synaptics Incorporated)
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [310912 2011-03-23] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-25] ()
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [41320 2011-04-04] (Lenovo Group Limited)
HKLM\...\Run: [ALCKRESI.EXE] C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [281960 2011-04-04] (Lenovo Group Limited)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-07-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-26] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [7406392 2012-11-28] (Logitech Inc.)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1631808 2012-02-27] (Lenovo Group Limited)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-02] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [37232 2008-06-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot [295072 2013-03-11] (RealNetworks, Inc.)
HKU\Default\...\RunOnce: [] [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe /DRIVE=Q [159744 2009-03-24] ()
HKU\Default User\...\RunOnce: [] [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] C:\PROGRA~2\Common~1\Lenovo\Lenovo~1\LenovoAutorunreg.exe /DRIVE=Q [159744 2009-03-24] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\TouchStartup.lnk
ShortcutTarget: TouchStartup.lnk -> C:\Program Files (x86)\TouchService\TouchStartup.exe (CVTouch)

==================== Services (Whitelisted) ===================

2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2012-09-12] (SUPERAntiSpyware.com)
2 ANSYS, Inc. License Manager; "C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\ansysli_server.exe" -nodaemon -k runservice [4954112 2011-10-17] (ANSYS, Inc.)
2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [198784 2010-12-16] (Conexant Systems Inc.)
2 hasplms; C:\Windows\system32\hasplms.exe -run [3750400 2009-12-16] (SafeNet Inc.)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-06] (Lenovo Group Limited)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22056 2013-01-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [379360 2013-01-26] (Microsoft Corporation)
2 RealNetworks Downloader Resolver Service; "C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe" [38608 2012-11-29] ()
2 SROSVC; C:\Program Files (x86)\Lenovo\Screen Reading Optimizer\SROSVC.exe [443240 2011-03-02] (Lenovo Group Limited)
2 VIPAppService; "C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe" [84088 2011-04-13] (Symantec Corporation)

==================== Drivers (Whitelisted) =====================

1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [270912 2011-10-25] (DT Soft Ltd)
3 Gun; \??\C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys [45176 2011-12-26] ()
2 HOSTNT; C:\Windows\System32\Drivers\HOSTNT.sys [13864 2012-10-15] (SafeNet, Inc.)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [230320 2013-01-19] (Microsoft Corporation)
3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-19] (Microsoft Corporation)
3 RzSynapse; C:\Windows\System32\Drivers\RzSynapse.sys [115200 2010-10-14] (Razer USA Ltd)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 TVTI2C; C:\Windows\System32\Drivers\TVTI2C.sys [41536 2009-09-24] (Lenovo (United States) Inc.)
3 vtany; \??\C:\Windows\vtany.sys [x]
3 X6va009; \??\C:\Windows\SysWOW64\Drivers\X6va009 [x]
3 X6va010; \??\C:\Windows\SysWOW64\Drivers\X6va010 [x]
3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [x]
3 xsherlock; C:\Windows\system32\xsherlock.xem [x]
3 xspirit; \??\C:\Windows\xspirit.sys [x]

==================== NetSvcs (Whitelisted) ====================


==================== One Month Created Files and Folders ========

2013-03-16 08:08 - 2013-03-16 08:08 - 00000000 ____D C:\FRST
2013-03-15 00:55 - 2013-03-15 00:55 - 00000000 __SHD C:\found.000
2013-03-11 22:57 - 2013-03-11 22:57 - 00201424 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00001042 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2013-03-11 22:57 - 2013-03-11 22:57 - 00000143 ____A C:\Users\Public\Desktop\RealPlay.url
2013-03-11 22:57 - 2013-03-11 22:57 - 00000000 ____D C:\ProgramData\RealNetworks
2013-03-11 22:57 - 2013-03-11 22:57 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-03-11 22:56 - 2013-03-11 22:56 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2013-03-11 22:56 - 2013-03-11 22:56 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2013-03-11 22:56 - 2013-03-11 22:56 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2013-02-28 22:29 - 2013-02-28 22:29 - 01085344 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-02-28 22:29 - 2013-02-28 22:29 - 00963488 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-02-28 22:29 - 2013-02-28 22:29 - 00310688 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-02-28 22:28 - 2013-02-28 22:29 - 00000000 ____D C:\Program Files\Java
2013-02-28 22:19 - 2013-02-28 22:19 - 00001830 ____A C:\Users\Public\Desktop\BlueJ.lnk
2013-02-28 22:18 - 2013-02-28 22:19 - 00000000 ____D C:\Program Files (x86)\BlueJ
2013-02-28 22:07 - 2013-02-28 22:07 - 00000000 ____D C:\Program Files (x86)\Red Sky
2013-02-27 11:01 - 2013-01-13 11:53 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-02-27 11:01 - 2013-01-13 11:24 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll
2013-02-27 11:01 - 2013-01-03 22:11 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll
2013-02-27 11:01 - 2013-01-03 22:11 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-02-27 11:00 - 2013-01-13 13:17 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:17 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:16 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:12 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:11 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:11 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:11 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:11 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 13:11 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:35 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:35 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:35 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:32 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:31 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 11:00 - 2013-01-13 12:22 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-02-27 11:00 - 2013-01-13 12:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-02-27 11:00 - 2013-01-13 12:09 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-02-27 11:00 - 2013-01-13 12:08 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-02-27 11:00 - 2013-01-13 12:08 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-02-27 11:00 - 2013-01-13 11:59 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-02-27 11:00 - 2013-01-13 11:58 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll
2013-02-27 11:00 - 2013-01-13 11:54 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-02-27 11:00 - 2013-01-13 11:53 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-02-27 11:00 - 2013-01-13 11:51 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2013-02-27 11:00 - 2013-01-13 11:49 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll
2013-02-27 11:00 - 2013-01-13 11:48 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-02-27 11:00 - 2013-01-13 11:46 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-02-27 11:00 - 2013-01-13 11:43 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-02-27 11:00 - 2013-01-13 11:38 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-02-27 11:00 - 2013-01-13 11:38 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2013-02-27 11:00 - 2013-01-13 11:38 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll
2013-02-27 11:00 - 2013-01-13 11:37 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-02-27 11:00 - 2013-01-13 11:25 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll
2013-02-27 11:00 - 2013-01-13 11:24 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2013-02-27 11:00 - 2013-01-13 11:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll
2013-02-27 11:00 - 2013-01-13 11:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2013-02-27 11:00 - 2013-01-13 11:15 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-02-27 11:00 - 2013-01-13 11:10 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2013-02-27 11:00 - 2013-01-13 11:02 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-02-27 11:00 - 2013-01-13 10:34 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-02-27 11:00 - 2013-01-13 10:32 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll
2013-02-27 11:00 - 2013-01-13 10:09 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-02-27 11:00 - 2013-01-13 09:26 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-02-27 11:00 - 2013-01-13 09:05 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll
2013-02-24 18:22 - 2013-02-24 18:22 - 00002030 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-02-23 11:01 - 2013-02-23 11:00 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-19 23:00 - 2013-02-19 23:00 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2013-02-19 23:00 - 2013-02-19 23:00 - 00000000 ___RD C:\Program Files (x86)\Skype

==================== One Month Modified Files and Folders =======

2013-03-15 00:55 - 2013-03-15 00:55 - 00000000 __SHD C:\found.000
2013-03-13 09:18 - 2011-10-13 01:49 - 01706987 ____A C:\Windows\WindowsUpdate.log
2013-03-13 09:16 - 2013-01-13 23:44 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-03-13 09:16 - 2013-01-13 23:44 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-03-13 08:31 - 2009-07-13 21:13 - 00779266 ____A C:\Windows\System32\PerfStringBackup.INI
2013-03-13 05:30 - 2011-10-25 04:38 - 00000466 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2013-03-13 05:12 - 2009-07-13 20:45 - 00024608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-03-13 05:12 - 2009-07-13 20:45 - 00024608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-03-13 05:05 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-03-13 05:05 - 2009-07-13 20:51 - 00139189 ____A C:\Windows\setupact.log
2013-03-11 22:58 - 2012-02-28 06:48 - 00000000 ____D C:\ProgramData\Real
2013-03-11 22:57 - 2013-03-11 22:57 - 00201424 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll
2013-03-11 22:57 - 2013-03-11 22:57 - 00001042 ____A C:\Users\Public\Desktop\RealPlayer.lnk
2013-03-11 22:57 - 2013-03-11 22:57 - 00000143 ____A C:\Users\Public\Desktop\RealPlay.url
2013-03-11 22:57 - 2013-03-11 22:57 - 00000000 ____D C:\ProgramData\RealNetworks
2013-03-11 22:57 - 2013-03-11 22:57 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-03-11 22:57 - 2012-02-28 06:48 - 00000000 ____D C:\Program Files (x86)\Real
2013-03-11 22:56 - 2013-03-11 22:56 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
2013-03-11 22:56 - 2013-03-11 22:56 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2013-03-11 22:56 - 2013-03-11 22:56 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll
2013-03-10 17:07 - 2011-10-25 04:38 - 00000528 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2013-03-05 09:18 - 2013-01-13 23:46 - 00002194 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-03-04 17:42 - 2009-07-13 21:08 - 00032542 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-03-04 10:46 - 2011-11-09 23:51 - 00000000 ____D C:\ProgramData\PMB Files
2013-03-02 01:11 - 2010-11-20 19:47 - 00226550 ____A C:\Windows\PFRO.log
2013-03-01 08:58 - 2011-12-01 22:19 - 00000000 ____D C:\Program Files (x86)\Steam
2013-02-28 22:29 - 2013-02-28 22:29 - 01085344 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2013-02-28 22:29 - 2013-02-28 22:29 - 00963488 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2013-02-28 22:29 - 2013-02-28 22:29 - 00310688 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00188832 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00188320 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2013-02-28 22:29 - 2013-02-28 22:29 - 00108448 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2013-02-28 22:29 - 2013-02-28 22:28 - 00000000 ____D C:\Program Files\Java
2013-02-28 22:27 - 2012-09-03 22:57 - 00000000 ____D C:\Program Files (x86)\1ClickDownload
2013-02-28 22:19 - 2013-02-28 22:19 - 00001830 ____A C:\Users\Public\Desktop\BlueJ.lnk
2013-02-28 22:19 - 2013-02-28 22:18 - 00000000 ____D C:\Program Files (x86)\BlueJ
2013-02-28 22:07 - 2013-02-28 22:07 - 00000000 ____D C:\Program Files (x86)\Red Sky
2013-02-27 12:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-02-27 12:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-02-27 12:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\zh-HK
2013-02-27 12:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\tr-TR
2013-02-24 18:22 - 2013-02-24 18:22 - 00002030 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-02-24 18:22 - 2011-10-13 02:08 - 00000000 ____D C:\ProgramData\Adobe
2013-02-24 18:21 - 2011-10-13 02:08 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-02-23 11:00 - 2013-02-23 11:01 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-02-23 11:00 - 2013-02-23 11:00 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-02-23 11:00 - 2012-10-14 05:34 - 00861088 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-02-23 11:00 - 2011-12-01 03:46 - 00782240 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-02-19 23:00 - 2013-02-19 23:00 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2013-02-19 23:00 - 2013-02-19 23:00 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-02-19 23:00 - 2012-02-13 06:31 - 00000000 ____D C:\ProgramData\Skype
2013-02-19 11:02 - 2012-04-29 22:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-02-19 11:02 - 2011-10-25 05:06 - 00002155 ____A C:\Windows\epplauncher.mif
2013-02-19 11:02 - 2011-10-25 05:05 - 00000000 ____D C:\Program Files\Microsoft Security Client


==================== Known DLLs (Whitelisted) =================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================


==================== Memory info ===========================

Percentage of memory in use: 15%
Total physical RAM: 4009.98 MB
Available physical RAM: 3399.42 MB
Total Pagefile: 4008.13 MB
Available Pagefile: 3387.71 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Partitions =============================

1 Drive c: (Windows7_OS) (Fixed) (Total:285.2 GB) (Free:138.56 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (Lenovo_Recovery) (Fixed) (Total:11.72 GB) (Free:3.62 GB) NTFS
3 Drive f: () (Removable) (Total:3.81 GB) (Free:3.6 GB) NTFS
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.84 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 3900 MB 0 B

Partitions of Disk 0:
===============

Disk ID: 4AE894F8

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1200 MB 1024 KB
Partition 2 Primary 285 GB 1201 MB
Partition 3 Primary 11 GB 286 GB

==================================================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM_DRV NTFS Partition 1200 MB Healthy

=========================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Windows7_OS NTFS Partition 285 GB Healthy

=========================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E Lenovo_Reco NTFS Partition 11 GB Healthy

=========================================================

Partitions of Disk 1:
===============

Disk ID: CE22FDDD

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3899 MB 384 KB

==================================================================================

Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F NTFS Removable 3899 MB Healthy

=========================================================
============================== MBR Partition Table ==================

==============================
Partitions of Disk 0:
===============
Disk ID: 4AE894F8

Partition 1:
=========
Hex: 80202100071B02990008000000802500
Active: YES
Type: 07 (NTFS)
Size: 1 GB

Partition 2:
=========
Hex: 001B039907FEFFFF00882500F857A623
Active: NO
Type: 07 (NTFS)
Size: 285 GB

Partition 3:
=========
Hex: 00FEFFFF07FEFFFF00E0CB2300007701
Active: NO
Type: 07 (NTFS)
Size: 12 GB

==============================
Partitions of Disk 1:
===============
Disk ID: CE22FDDD

Partition 1:
=========
Hex: 800C0D0007FE7FF00003000000DD7900
Active: YES
Type: 07 (NTFS)
Size: 4 GB


Last Boot: 2013-03-05 19:32

==================== End Of Log =============================
  • 0

#4
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
There is no sign of infection or problems that may contribute to this behavior. Lets restore the registry to 2013-03-05.

Download the enclosed file.

Save it next to FRST64.

Run FRST64 as you did before, except that this time around, click on the Fix button and wait.

The tool will make a log in the flashdrive (Fixlog.txt) please post it to your reply.

Attempt to boot in Normal Mode and let me know the outcome.
  • 0

#5
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Normal boot ended up with a BSOD after the windows 7 logo and the computer restarts.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2013
Ran by SYSTEM at 2013-03-16 12:44:21 Run:1
Running from F:\

==============================================

DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.

==== End of Fixlog ====

Good to know the system isnt infected, although boot up is still failing :( .
  • 0

#6
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Lets take a look at the BlueScreen error message.

  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:

    Posted Image

  • When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:
Posted Image


Please post me the Stop error message.
  • 0

#7
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
A problem has been detected and windows has been shut down to prevent damage to your computer.

If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:

Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run CHKDSK /F to check for hard drive corruption, and then restart computer.

Technical Information:
*** STOP: 0x0000007B (0xFFFFF880009A97E8, 0xFFFFFFFFC0000034, 0X0000000000000000, 0X0000000000000000)


That is all that is displayed on my BSOD.
  • 0

#8
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
For x86 (x32) bit systems please download Listparts
For x64 bit systems please download Listparts64
and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Click on Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\ListParts.exe (for x64 bit version type e:\ListParts64.exe) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Put check mark on List BCD.
  • Press Scan button.
  • It will make a log (Result.txt) in the flash drive. Please copy and paste it to your reply.

  • 0

#9
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
x:\windows\system32\f:\listparts64.exe
The application has failed to start because its side by side configuration is incorrect. Please see the application event log or use the command-line sxstrace.exe tool for more detail.
  • 0

#10
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Lets check the master boot record.

Download the enclosed file.

Save it in the USB drive, next to FRST64.

Insert the USB drive into the ailing computer.

Now please enter System Recovery Options and run FRST64 as you did before, except that this time around, press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt). It will also create a file labeled MBRDUMP.txt. Copy and Paste the contents of the Fixlog.txt in your next reply, but attach the MBRDUMP.txt as it is a hex file.
  • 0

Advertisements


#11
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
fixlog.txt
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2013
Ran by SYSTEM at 2013-03-17 14:30:43 Run:2
Running from F:\

==============================================

MBRDUMP.txt is made successfully.

========= bcdedit /enum all /v =========


Windows Boot Manager
--------------------
identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device partition=Y:
path \bootmgr
description Windows Boot Manager
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
extendedinput Yes
default {b3bbc210-f57c-11e0-a4ca-e89a8ffa3c83}
resumeobject {b3bbc20f-f57c-11e0-a4ca-e89a8ffa3c83}
displayorder {b3bbc210-f57c-11e0-a4ca-e89a8ffa3c83}
toolsdisplayorder {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout 0
customactions 0x10000ba000001
0x54000001
custom:54000001 {d0572c25-ff05-11e0-b51d-402cf468fb3c}
custom:5400000f {d0572c25-ff05-11e0-b51d-402cf468fb3c}

Windows Boot Loader
-------------------
identifier {b3bbc210-f57c-11e0-a4ca-e89a8ffa3c83}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
recoverysequence {d0572c25-ff05-11e0-b51d-402cf468fb3c}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {b3bbc20f-f57c-11e0-a4ca-e89a8ffa3c83}
nx OptIn

Windows Boot Loader
-------------------
identifier {d0572c25-ff05-11e0-b51d-402cf468fb3c}
device ramdisk=[Y:]\Recovery\WindowsRE\Winre.wim,{d0572c26-ff05-11e0-b51d-402cf468fb3c}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
osdevice ramdisk=[Y:]\Recovery\WindowsRE\Winre.wim,{d0572c26-ff05-11e0-b51d-402cf468fb3c}
systemroot \windows
nx OptIn
winpe Yes
custom:46000010 Yes

Resume from Hibernate
---------------------
identifier {b3bbc20f-f57c-11e0-a4ca-e89a8ffa3c83}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {1afa9c49-16ab-4a5c-901b-212802da9460}
filedevice partition=C:
filepath \hiberfil.sys
debugoptionenabled No

Windows Memory Tester
---------------------
identifier {b2721d73-1db4-4c62-bf78-c548a880142d}
device partition=Y:
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
badmemoryaccess Yes

EMS Settings
------------
identifier {0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
bootems Yes

Debugger Settings
-----------------
identifier {4636856e-540f-4170-a130-a84776f4c654}
debugtype Serial
debugport 1
baudrate 115200

RAM Defects
-----------
identifier {5189b25c-5558-4bf2-bca4-289b11bd29e2}

Global Settings
---------------
identifier {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
inherit {4636856e-540f-4170-a130-a84776f4c654}
{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
{5189b25c-5558-4bf2-bca4-289b11bd29e2}

Boot Loader Settings
--------------------
identifier {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
{7ff607e0-4395-11db-b0de-0800200c9a66}

Hypervisor Settings
-------------------
identifier {7ff607e0-4395-11db-b0de-0800200c9a66}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Resume Loader Settings
----------------------
identifier {1afa9c49-16ab-4a5c-901b-212802da9460}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}

Setup Ramdisk Options
---------------------
identifier {ae5534e0-a924-466c-b836-758539a3ee3a}
description Ramdisk options
ramdisksdidevice boot
ramdisksdipath \boot\boot.sdi

Device options
--------------
identifier {d0572c26-ff05-11e0-b51d-402cf468fb3c}
description Ramdisk Options
ramdisksdidevice partition=Y:
ramdisksdipath \Recovery\WindowsRE\boot.sdi

========= End of CMD: =========


==== End of Fixlog ====


MBRDUMP.txt

3м |ؾ |  Ph ~ | V UFF AU]rUu  tFf`~ t&fh fvh h |h h BV  |V vNnfasNu ~  U2V ]랁>}Uunv ud `| du f#u;fTCPAu2r,fh fh  fh fSfSfUfh fh | fah Z2 | 2 < t  +d $$Invalid partition table Error loading operating system Missing operating system c{J !   %  % W#  # w U



Well that could explain a lot of things.....
  • 0

#12
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
You must attach the MBRDUMP.txt as it is a hex file.
  • 0

#13
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Sorry my mistake

Attached Files


  • 0

#14
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
All partitions and boot record seem clear.

Boot to the prompt. At the prompt type the following and press Enter:

CHKDSK C: /R

Please let me know if there are bad sectors or clusters.
  • 0

#15
monkeyboyvin

monkeyboyvin

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
x:\windows\system32>CHKDSK C:/R
The type of the file system is NTFS.
Volume label is SYSTEM_DRV.

CHKDSK is verifying files <stage 1 of 5>...
144 file records processed.
File verification Completed.
0 large file records processed.
0 bad file records processed.
0 EA records processed.
0 reparse records processed.
CHKDSK is verifying indexes <stage 2 of 5>...
226 index entries processed.
Index verification completed.
0 unindexed files scanned.
0 unindexed files recovered.
CHKDSK is verifying security descriptors <stage 3 of 5>...
144 file SDs/SIDs processed.
Security descriptor verification completed.
42 data files processed.
CHKDSK is verifying Usn Journal...
611688 USN bytes processed.
Usn Journal verification completed.
CHKDSK is verifying file data < stage 4 of 5>...
Windows replaced bad clusters in file 36 of name \Boot\BOOTSTAT.DAT.
128 files processed.
File data verification completed.
CHKDSK is verifying free space <stage 5 of 5>...
218658 free clusters processed.
Free space verification is complete.
Adding 1 bad cluster to the Bad Clusters File.
Correcting errors in the Volume Bitmap.
Windows has made corrections to the file system.

1228799 KB total disk space.
344508 KB in 66 files.
28 KB in 43 indexes.
4 KB in bad sectors.
9623 KB in use by the system.
8192 KB occupied by the log file.
874636 KB available on disk.

4096 bytes in each allocation unit.
307199 total allocation units on disk.
218659 allocation units available on disk.

Failed to transfer logged messages to the event log with status 50.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP