Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus Infection - Programmes Disabled


  • Please log in to reply

#61
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load:  AFD aswRdr aswRvrt aswSnx aswSP aswVmm Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL 
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:56:17
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:  A device attached to the system is not functioning.  
 
Log: 'System' Date/Time: 05/12/2015 12:55:51
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 
 
Log: 'System' Date/Time: 05/12/2015 12:55:43
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 
 
Log: 'System' Date/Time: 05/12/2015 12:53:02
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\WINDOWS\system32\SHELL32.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 05/12/2015 12:53:02
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 05/12/2015 12:52:17
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\2057\UILangRes.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 05/12/2015 12:52:17
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Avast.VC110.CRT. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 05/12/2015 12:52:16
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\aswRemoteCache.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 05/12/2015 12:52:16
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Avast.VC110.CRT. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 05/12/2015 12:51:57
Type: error Category: 0
Event: 7034 Source: Service Control Manager
The COM+ System Application service terminated unexpectedly.  It has done this 3 time(s). 
 
Log: 'System' Date/Time: 05/12/2015 12:51:46
Type: error Category: 0
Event: 7031 Source: Service Control Manager
The COM+ System Application service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service. 
 
Log: 'System' Date/Time: 05/12/2015 12:51:46
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\aswAra.dll. Reference error message: The operation completed successfully. . 
 
Log: 'System' Date/Time: 05/12/2015 12:51:46
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Avast.VC110.CRT. Reference error message: Insufficient system resources exist to complete the requested service. . 
 
Log: 'System' Date/Time: 05/12/2015 12:51:44
Type: error Category: 0
Event: 7031 Source: Service Control Manager
The COM+ System Application service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service. 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • 0

Advertisements


#62
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 05/12/2015 12:51:57
Type: error Category: 8
Event: 4689 Source: COM+
The run-time environment has detected an inconsistency in its internal state. This indicates a potential instability in the process that could be caused by the custom components running in the COM+ application, the components they make use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\crm\recoveryclerk2.cpp(1192), hr = 800705aa: InitNew
 
Log: 'Application' Date/Time: 05/12/2015 12:51:46
Type: error Category: 8
Event: 4689 Source: COM+
The run-time environment has detected an inconsistency in its internal state. This indicates a potential instability in the process that could be caused by the custom components running in the COM+ application, the components they make use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\crm\recoveryclerk2.cpp(1192), hr = 800705aa: InitNew
 
Log: 'Application' Date/Time: 05/12/2015 12:51:43
Type: error Category: 8
Event: 4689 Source: COM+
The run-time environment has detected an inconsistency in its internal state. This indicates a potential instability in the process that could be caused by the custom components running in the COM+ application, the components they make use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\crm\recoveryclerk2.cpp(1192), hr = 800705aa: InitNew
 
Log: 'Application' Date/Time: 05/12/2015 12:51:43
Type: error Category: 0
Event: 0 Source: Media Center Scheduler
The event description cannot be found.
 
Log: 'Application' Date/Time: 05/12/2015 12:51:31
Type: error Category: 0
Event: 0 Source: Media Center Scheduler
The event description cannot be found.
 
Log: 'Application' Date/Time: 05/12/2015 12:51:03
Type: error Category: 0
Event: 1041 Source: Userenv
Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. 
 
Log: 'Application' Date/Time: 05/12/2015 12:51:03
Type: error Category: 0
Event: 1041 Source: Userenv
Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. 
 
Log: 'Application' Date/Time: 05/12/2015 12:51:03
Type: error Category: 0
Event: 1041 Source: Userenv
Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration. 
 
Log: 'Application' Date/Time: 05/12/2015 12:51:03
Type: error Category: 0
Event: 1041 Source: Userenv
Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration. 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 05/12/2015 12:51:56
Type: warning Category: 105
Event: 4445 Source: COM+
An incompletely initialized CRM log file was detected. It has been re-initialized. If this warning appears when the CRM log file is being initially created then no further action is required.  Server Application ID: {02D4B3F1-FD88-11D1-960D-00805FC79235} Server Application Instance ID: {0C64E7C4-ADE4-49DF-A80B-44F98C6CA865} Server Application Name: System Application Comsvcs.dll file version: ENU 2001.12.4414.702 shp
 
Log: 'Application' Date/Time: 05/12/2015 12:51:45
Type: warning Category: 105
Event: 4444 Source: COM+
An empty CRM log file was detected. It has been re-initialized. If this warning appears when the CRM log file is being initially created then no further action is required.  Server Application ID: {02D4B3F1-FD88-11D1-960D-00805FC79235} Server Application Instance ID: {89F26ACC-2140-4C6B-ACB0-C793BCED1984} Server Application Name: System Application Comsvcs.dll file version: ENU 2001.12.4414.702 shp
 
Log: 'Application' Date/Time: 05/12/2015 12:51:42
Type: warning Category: 105
Event: 4444 Source: COM+
An empty CRM log file was detected. It has been re-initialized. If this warning appears when the CRM log file is being initially created then no further action is required.  Server Application ID: {02D4B3F1-FD88-11D1-960D-00805FC79235} Server Application Instance ID: {2523591F-DC0E-4C8A-9C15-9361DA263692} Server Application Name: System Application Comsvcs.dll file version: ENU 2001.12.4414.702 shp

  • 0

#63
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

after running sfc /scannow a box opens up momentarily 

sigverif: all of the dates are quite old.theres nothing from 2015.however there is one that has a date listed as unknown.

syntplpr.exe   


  • 0

#64
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Copy the next line:

 

reg query "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\SubSystems\Windows" /s > \junk.txt

 

Start, Run and click in the Run box and Ctrl + v.  Hit Enter.

 

Repeat for

 

notepad \junk.txt


  • 0

#65
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

error message received , unable to  find


  • 0

#66
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

try:

 

Copy the next line:

 

reg query "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager" /s > \junk.txt

 

Start, Run and click in the Run box and Ctrl + v.  Hit Enter.

 

Repeat for

 

notepad \junk.txt


  • 0

#67
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

nothing happens.

notepad opens and the cursor blinks.


  • 0

#68
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Going to have to dig up my old XP netbook and see what I can find on it.  More tomorrow.


  • 0

#69
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

Cool.

Thanks for all your assistance and patience so far.


  • 0

#70
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Attached is a zip file.  Download and save then right click and Extract All.  That should give you sesmgr.reg.

 

Put sesmgr.reg on the sick PC and then right click and Merge.  OK.

 

This should replace some critical parts of your registry.  

 

See if you are now able to Start, Run, cmd, Enter.


  • 0

Advertisements


#71
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

I had to restart the computer after I merged  sesmgr.reg.

And now it won't reboot.

Either in normal mode or safe mode.

Its in a restarting loop. 


  • 0

#72
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Did you make a Hiren's Boot Disk?

 

See if you can boot from it.


  • 0

#73
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

I tried the hiren boot disk and chose the 'boot from hard drive'  option , with no joy.


  • 0

#74
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

No, boot hiren's and then chose miniXP 

 

Then start at Step two on http://raygibson.net/kb/040129/

 

and see if you can find an old restore point to copy as they do.  


  • 0

#75
elielieli

elielieli

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 174 posts

Ive located the RPs in c drive , but can't follow the instructions:

 

 

"Type "cd _restore{CDSFSD"+tab or whatever the name of the directory is and do another 'dir'. If you see nothing, "cd .." and then go into the other one."

When it say 'or' is it referring to 'cd _restore{CDSFSD"+tab' or only part of it and is this to be typed into the cmd?

Also , whats a dir , how do i carry one out?


Edited by elielieli, 13 December 2015 - 08:02 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP