Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Shutdown errors


  • Please log in to reply

#16
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
When you typed in: sfc /?
did you get any response?

Please download MiniToolBox, save it to your desktop and run it by right clicking and Run As Admin.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer Errors
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
  • 0

Advertisements


#17
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
:)

Attached Files


  • 0

#18
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
Uninstall Spybot S&D if you haven't already. Go into Services (Search for services.msc then when it finds it right click on it and run as admin. Find the SBSD Security Center Service (If it still exists) and right click on it and select Properties. Change the Startup Type: to Disabled then OK.

That should get rid of these errors:

Error: (07/31/2013 09:23:51 PM) (Source: Service Control Manager) (User: )
Description: Tjenesten SBSD Security Center Service kunne ikke starte pga. følgende fejl:
%%1053

Error: (07/31/2013 09:23:51 PM) (Source: Service Control Manager) (User: )
Description: Der opstod timeout (30000 millisekunder), mens systemet ventede på, at der blev oprettet forbindelse til tjenesten SBSD Security Center Service.


Copy the next 3 lines:

reg query HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control > %userprofile%\desktop\junk.txt
sfc /scanfile=c:\windows\explorer.exe >> %userprofile%\desktop\junk.txt
notepad %userprofile%\desktop\junk.txt

In the search box type in cmd.exe and when it finds it, right click on it and Run As Admin.

Right click and Paste or Edit then Paste and the copied lines should appear. Hit Enter. Notepad should open. Copy and paste the text from notepad. If too big you can attach the junk.txt file on your desktop.

Download and Save the attached regsize.reg file. Right click on it and Merge. This is supposed to be a fix for the error:

Error: (07/31/2013 09:47:53 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT AUTHORITY)
Description: CBS-klienten blev ikke installeret. Seneste fejl: 0x80080005


Clear the errors as before. Reboot and run the minitoolbox with just the List last 10 Event Viewer Errors checked. Copy and paste the text from minitoolbox into a reply.
  • 0

#19
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
The note pad document is empty - and I cannot see any attached file here?

Edited by aalborgenser, 01 August 2013 - 11:18 AM.

  • 0

#20
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
Try just

reg query HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control

Do you get any text?

then try

sfc /scanfile=c:\windows\explorer.exe


Do you get any text?
  • 0

#21
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control
PreshutdownOrder REG_MULTI_SZ wuauserv\0gpsvc\0trustedinstaller
WaitToKillServiceTimeout REG_SZ 12000
CurrentUser REG_SZ USERNAME
BootDriverFlags REG_DWORD 0x0
ServiceControlManagerExtension REG_EXPAND_SZ %systemroot%\system32\sce
xt.dll
SystemStartOptions REG_SZ NOEXECUTE=OPTIN
SystemBootDevice REG_SZ multi(0)disk(0)rdisk(0)partition(2)
FirmwareBootDevice REG_SZ multi(0)disk(0)rdisk(0)partition(1)

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ACPI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\AGP
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\AppID
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Arbiters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\BackupRestore
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CoDeviceInstallers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\COM Name Arbiter
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ContentIndex
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CrashControl
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CriticalDeviceDatabase
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Cryptography
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\DeviceClasses
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\DeviceOverrides
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Diagnostics
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Els
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Errata
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystem
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\FileSystemUtilities
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\GraphicsDrivers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\GroupOrderList
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\HAL
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\IDConfigDB
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layout
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaInformation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaCategories
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaDRM
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaInterfaces
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaProperties
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaResources
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaSets
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MediaTypes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MobilePC
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPDEV
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MSDTC
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MUI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NetDiagFx
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NetTrace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Network
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NetworkProvider
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NodeInterfaces
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nsi
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\PCW
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\PnP
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\PriorityControl
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ProductOptions
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Remote Assistance
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\RtlQueryRegistryConfig
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ScsiPort
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ServiceGroupOrder
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ServiceProvider
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SNMP
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SQMServiceList
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Srp
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SrpExtensionConfig
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StillImage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Storage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemResources
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TabletPC
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TimeZoneInformation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Ubpm
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\usbflags
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\usbstor
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\VAN
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Video
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\VirtualDeviceDrivers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\wcncsvc
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Wdf
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Winlogon
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WMI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WOW
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\hivelist
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Winresume

________________

No text using the next command.

Edited by aalborgenser, 01 August 2013 - 04:02 PM.

  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
Copy the text in the code box:

/md5start
sfc.com
sfc.cmd
sfc.exe
sfcfiles.dll
sfccom.dll
sfc_os.dll
/md5stop

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.
  • 0

#23
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
:)

Attached Files


  • 0

#24
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
One more time:

Copy the text in the code box:

/md5start
sfc.dll
/md5stop

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes


Then Run Scan.
  • 0

#25
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Here it is.

Attached Files

  • Attached File  OTL.Txt   122.94KB   18 downloads

  • 0

Advertisements


#26
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
I tried running sfc /scannow on my PC and ran Process Explorer at the same time. It said that the files in the following list were used for SFC so let's see if they are present.

Copy the text in the code box:

/md5start
advapi32.dll
apisetschema.dll
cfgmgr32.dll
clbcatq.dll
cryptbase.dll
cryptsp.dll
devobj.dll
gdi32.dll
imm32.dll
kernel32.dll
KernelBase.dll
locale.nls
lpk.dll	Language Pack
msctf.dll
msvcrt.dll
ntdll.dll
ole32.dll
oleaut32.dll
powrprof.dll
rpcrt4.dll
RpcRtRemote.dll
rsaenh.dll
sechost.dll
setupapi.dll
sfc.exe
sfc.exe.mui
SortDefault.nls			
user32.dll
usp10.dll
uxtheme.dll
version.dll
wrpintapi.dll
/md5stop

Run OTL (Vista or Win 7 => right click and Run As Administrator)


Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

then Run Scan.

You should get 1 log. Please copy and paste it. (If you want to speed it up you can check all of the None boxes before Run Scan. )
  • 0

#27
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Good night, thanks and see U tomorrow (2:51 AM here now).

Attached Files

  • Attached File  OTL.Txt   79.9KB   77 downloads

  • 0

#28
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
Get some sleep. Don't think it's worth staying up so late for.

I messed up one of them. Could you run this one again?

/md5start
lpk.dll
/md5stop
  • 0

#29
aalborgenser

aalborgenser

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
As requested.

Attached Files

  • Attached File  OTL.Txt   38.39KB   34 downloads

  • 0

#30
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,028 posts
  • MVP
All files seem to be present and all but the one which is Danish language specific (ends in .mui) have valid checksums. Hard to tell on the Danish one. Let's see if Process Monitor can see why sfc won't run.

Download and Save to your desktop Process Monitor http://live.sysinter...com/Procmon.exe

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Type but don't hit Enter yet:

sfc  /scannow


Leave the Command Window and go back to the desktop and right click procmon.exe and Run As Admin.

As soon as Process Monitor starts filling the screen, go back to the Command Window and hit Enter.

As soon as it accepts the command, go back to Process Monitor and select File, then uncheck Capture Events. Once it stops,

Filter, Filter. Change Architecture to Process Name. Change the blank box by clicking on its down arrow and then scroll down to sfc.exe and select it. Then click on Add and then OK.


File, Save, Events displayed Using Current filter, Format: Comma-Separated Values (CSV) then (Make sure the path points to your desktop) OK. It should save the file to logfile.csv which should be on your desktop. Close Process Monitor. Zip up the logfile.pml and attach it to a Reply. (You can also just rename it to logfile.txt and attach it if you don't 7-zip or winzip)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP