Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Computer boots into Windows after restart only, can't enter setup


  • This topic is locked This topic is locked

#1
Andro

Andro

    Member

  • Member
  • PipPipPip
  • 228 posts

Hello,

 

my computer won't boot into windows when I turn it on, it freezes at startup when logo appears. After restart it boots normally. When I get into bios I can't enter setup in boot menu, it freezes again, there is just black screen.

 

FRST report attached...

 

Thanks for your help !

Attached Files

  • Attached File  FRST.txt   45.39KB   67 downloads

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

Can you post the Addition.txt file that should have been generated at the same time as FRST.txt?


  • 0

#3
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

Yes of course, here u go

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-07-2021 01
Ran by Tom (21-07-2021 19:10:12)
Running from E:\Programi za popravljanje
Windows 10 Pro Version 20H2 19042.1052 (X64) (2021-07-01 14:58:47)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3547423862-3492151725-1014740435-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3547423862-3492151725-1014740435-503 - Limited - Disabled)
Guest (S-1-5-21-3547423862-3492151725-1014740435-501 - Limited - Disabled)
Tom (S-1-5-21-3547423862-3492151725-1014740435-1001 - Administrator - Enabled) => C:\Users\Tom
WDAGUtilityAccount (S-1-5-21-3547423862-3492151725-1014740435-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Panda Dome (Enabled - Up to date) {8EE5B6CC-D555-4755-164C-336E561DE601}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Panda Firewall (Enabled) {B6DE37E9-9F3A-460D-3D13-9A5BA8CEA17A}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version:  - Adobe)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 91.0.864.59 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - sl-si (HKLM\...\ProPlus2019Volume - sl-si) (Version: 16.0.14131.20278 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3547423862-3492151725-1014740435-1001\...\OneDriveSetup.exe) (Version: 21.109.0530.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{E5A95BC5-81DF-4F0C-B910-B59DD012F037}) (Version: 2.81.0.0 - Microsoft Corporation)
Mozilla Firefox 89.0.2 (x64 sl) (HKLM\...\Mozilla Firefox 89.0.2 (x64 sl)) (Version: 89.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 89.0.2 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Panda Devices Agent (HKLM-x32\...\{DB0164A2-ADE9-4FEE-B080-D506BDD6427F}) (Version: 1.08.09 - Panda Security) Hidden
Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.09 - Panda Security) Hidden
Panda Dome (HKLM\...\{EF4168C0-095F-4CFC-8CB3-139A11AC89BE}) (Version: 11.53.00 - Panda Security) Hidden
Panda Dome (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 20.02.01.0000 - Panda Security)
qBittorrent 4.3.6 (HKLM-x32\...\qBittorrent) (Version: 4.3.6 - The qBittorrent project)
WinRAR 6.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)

Packages:
=========
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-07-02] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-07-02] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.6151.0_x64__8wekyb3d8bbwe [2021-07-02] (Microsoft Studios) [MS Ad]
Pošta in Koledar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0 [2021-07-01] (Spotify AB) [Startup Task]
Vreme MSN -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2020-12-02] (Panda Security S.L. -> Panda Security, S.L.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2020-12-02] (Panda Security S.L. -> Panda Security, S.L.)
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2020-12-02] (Panda Security S.L. -> Panda Security, S.L.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2015-03-17 06:34 - 2015-03-17 06:34 - 000010240 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\locale\sl_si\acrotray.slv

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-03-06] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-07-01] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-07 11:14 - 2019-12-07 11:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3547423862-3492151725-1014740435-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8A8C86B0-C577-44D3-9A4D-3C763131D91D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{391A8500-1913-405A-B31C-E5C2D9830C97}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1B0494AA-FD96-4B2F-AA9D-A390D3BB9C50}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{4D61E29B-BE5B-4A91-813B-B6C4DD48C0AE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3A527F05-5D06-4BE7-8349-73CCB4647720}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{0C733406-ECBD-45B9-B251-C6B6097F2C7E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{C4A89021-DD09-4C56-B8C0-A5F765C0ED35}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2077DDD6-9893-42C9-BC24-76F22EA3C0D4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9E9BA9D5-2219-4C98-B45A-308621E4C1B5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E101AC2E-4960-4650-B37C-0A5CF9BACFA6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.162.583.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B0B810FF-A223-4D0B-A4D3-12F9484F0A85}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{E886AFCF-5E55-48BF-B412-C0E003EA0CCE}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{A950350A-A987-4742-99C1-644296189F8D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BDD8ECBC-91AD-4F3E-96A0-2B635AFA32BD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{835E6C6E-FBA3-4D08-8169-DDF773B24CCA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{DC5E8845-4AB9-4DBE-802F-06060166018E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5B44731C-AE95-4EB5-A07E-E68AF3BB42BF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.72.94.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

==================== Restore Points =========================


==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (07/21/2021 07:07:56 PM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: )
Description: Event-ID 12007

Error: (07/21/2021 07:07:56 PM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: )
Description: Event-ID 0

Error: (07/21/2021 09:57:43 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (07/21/2021 09:57:38 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (07/21/2021 09:52:17 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (07/21/2021 09:49:54 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (07/21/2021 01:31:07 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0xC004F074
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (07/21/2021 01:23:02 AM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: )
Description: Event-ID 12007


System errors:
=============
Error: (07/21/2021 07:03:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-KL1F59U)
Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout.

Error: (07/21/2021 07:03:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-KL1F59U)
Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout.

Error: (07/21/2021 07:03:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-KL1F59U)
Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout.

Error: (07/21/2021 07:02:24 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:37:09 on ‎21. ‎07. ‎2021 was unexpected.

Error: (07/21/2021 07:02:14 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221226513A fatal error occurred processing the restoration data.

Error: (07/21/2021 09:49:40 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 01:30:54 on ‎21. ‎07. ‎2021 was unexpected.

Error: (07/21/2021 01:13:47 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume C:.

The exact nature of the corruption is unknown.  The file system structures need to be scanned and fixed offline.

Error: (07/21/2021 01:13:47 AM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY)
Description: C:\Device\HarddiskVolume33


==================== Memory info ===========================

BIOS: American Megatrends Inc. F1 04/08/2013
Motherboard: Gigabyte Technology Co., Ltd. 970A-DS3P
Processor: AMD FX™-6200 Six-Core Processor
Percentage of memory in use: 16%
Total physical RAM: 16346.73 MB
Available physical RAM: 13582.94 MB
Total Virtual: 19290.73 MB
Available Virtual: 16422.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:223.03 GB) (Free:182.56 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:930.5 GB) NTFS
Drive e: (Transcend) (Removable) (Total:3.73 GB) (Free:1.89 GB) FAT32

\\?\Volume{bdb3182d-0000-0000-0000-100000000000}\ (Rezerviran sistem) (Fixed) (Total:0.05 GB) (Free:0.02 GB) NTFS
\\?\Volume{bdb3182d-0000-0000-0000-20c537000000}\ () (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: BDB31827)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: BDB3182D)
Partition 1: (Active) - (Size=50 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=500 MB) - (Type=27)

==========================================================
Disk: 2 (Protective MBR) (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Attached Files


  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP
Error: (07/21/2021 01:13:47 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume C:.

The exact nature of the corruption is unknown.  The file system structures need to be scanned and fixed offline.

 

 

Type:

cmd

in the Search box and it should find Command Prompt

then click on the Run As Administrator option

Type:

chkdsk  /r  c:

in the command window and hit Enter.  Hit

y

when it asks you if you want to schedule it for the next reboot.

 

Then Restart.

 

The Disk check should start when the PC reboots.

 

If we are lucky this may fix the problem. 

 

Let's also check the system files to make sure they haven't gotten messed up:

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   414bytes   70 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again but this time make sure Addition.txt is checked and hit Scan.  Post both logs.


 

 



 


  • 0

#5
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

Fix log, FRST & Addition attached

Attached Files


  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

Did that help?  If not rerun FRST but check: List BCD (do not uncheck Addition.txt)  Post both logs.


  • 0

#7
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

It helps until I get into boot menu in bios. When I enter setup there, black screen appears and computer freezes. After restart I can't boot into windows until I restart again so I think problem is still here.

 

Here r both logs

Attached Files


  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

I don't see anything wrong in the Boot loader info.  Appears this was a Win 7 that was updated to Win 10 so slightly different from mine. 

 

If I understand you correctly if you boot normally into Windows there is no longer a problem but if you try to go into BIOS setup it gives you a black screen?

 

What is the make and model of your PC?

 

Let's get some more info on the PC:

 

Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.


 


  • 0

#9
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

If I understand you correctly if you boot normally into Windows there is no longer a problem but if you try to go into BIOS setup it gives you a black screen?

Exactly.

 

Can't say rhe make and model of PC because there is only this...To be filled by O:E.M: I guess this is because it's build up computer ?

Attached Files


  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

OK.  It's a Gigabyte motherboard 970A-DS3P which is mostly what I needed to know.  There is a newer BIOS but it says Beta so I think we will wait on trying to update it.

 

Probably the best thing to try is to Clear the CMOS.  This will put the BIOS back to the default values.  Shut it down, unplug it and open the case.  There are a pair of pins on the motherboard with the label: CLR_CMOS

They are just behind the 6 SATA connectors and just above the F connector.  See page 11 in the manual.  Available at:

https://www.gigabyte...#support-manual

(I'm looking at the English version).  Use a screwdriver or piece of wire or a jumper and short the pins together for 3 seconds.  When you put it back together and power it up it may want you to set the clock and load defaults.

 

Always turn off your computer and unplug the power cord from the power outlet before clearing the CMOS values.
•• After system restart, go to BIOS Setup to load factory defaults (select Load Optimized Defaults) or manually
configure the BIOS settings (refer to Chapter 2, "BIOS Setup," for BIOS configurations).

 


  • 0

Advertisements


#11
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

Did that and unfortunately is even worse, now I can't get into windows even after restart.

Attached Thumbnails

  • IMG_20210721_1406071.jpg

  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

Are you able to get into the BIOS setup now?  If so try setting it to defaults.  If not, try pulling the CMOS battery.  Leave it out for a while then put it back.


  • 0

#13
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

It's not a problem getting into the bios setup, problem is getting in setup in boot menu, I can choose 1st or 2nd disk to boot from, but if I choose enter setup the screen goes black, please check attached photos.

 

I removed the battery and load default settings but it's the same, still freezes.

Attached Thumbnails

  • IMG_20210727_0111551.jpg
  • IMG_20210727_0112431.jpg

  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,949 posts
  • MVP

OK.  The Kingston is your boot drive so try turning the PC off and disconnecting the Toshiba.  The BIOS may have a problem deciding which to use.  Looking at the manual I don't see the Setup option so perhaps having only one drive will make it happier.

 

Looking at the defaults for the BIOS I do see one that is rather obsolete.

 

OnChip SATA Type
Enables or disables RAID for the SATA controllers integrated in the AMD Chipset or configures the SATA
controllers to AHCI mode.
Native IDE Configures the SATA controller to IDE mode. (Default) <==This seems wrong.  You have a SATA drive and not an IDE so you probably need to change it to ACHI.  RAID might also work but I can't see IDE working.
RAID Enables RAID for the SATA controller.
AHCI Configures the SATA controllers to AHCI mode. Advanced Host Controller Interface
(AHCI) is an interface specification that allows the storage driver to enable advanced
Serial ATA features such as Native Command Queuing and hot plug.


  • 0

#15
Andro

Andro

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 228 posts

Should I do both things or try disconnecting Toshiba first ? If both, how do I change IDE to ACHI ?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP