Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - garegin

Pages: 1 2 [3] 4
51
General Computer Support / Re: sfc fails, says check CBS.log
« on: July 24, 2015, 04:18:32 am »
I don't have the computer with me right now, but I already ran a chkdsk /f on the volume.
as for the sfc error, it said "Windows Resource Protection found corrupt files but was unable to fix some of them"

52
General Computer Support / Re: sfc fails, says check CBS.log
« on: July 23, 2015, 07:42:07 pm »
ok. here is sfcdetails

53
General Computer Support / sfc fails, says check CBS.log
« on: July 23, 2015, 02:58:38 pm »
my MMC console doesn't work and it says "no audio output device is enabled". I did a sfc /scannow and it says check cbs.log

54
General Computer Support / recycle bin is hijacked.
« on: July 08, 2015, 10:27:22 am »
Ok, so when I try to erase the trash can I get.
"This file does not have a program associated with it for performing this action. Please install a program or, if one is already installed, create an association in the Default Program control panel."

The right click context menu for the recycle bin is also altered.

It says

Open
empty
Create Shortcut
Rename
Properties.

Notice that the empty is in lowercase, this is sign that it was modified by the malware.

55
ok
this is the new link to the log file. It's 800MB, so will take some time to download.

https://drive.google.com/file/d/0B1lqZhpyr-KQcWdtRDRDUkJRcU0/view?usp=sharing
takes me a couple seconds to download i have 100mbs per second ha lol and dang why so big?

would you have any ideas what's causing it?


56
It becomes big if you run it for a minute or two

57
ok
this is the new link to the log file. It's 800MB, so will take some time to download.

https://drive.google.com/file/d/0B1lqZhpyr-KQcWdtRDRDUkJRcU0/view?usp=sharing

58
the .PML log file was created by process monitor. So it definitely shows shutdown.exe being called by I don't know by what.

59
i got nothing with process explorer but can clearly see shutdown.exe (which is really renamed notepad.exe) called many times in the log. Can someone please take a look at the log file on google drive

https://drive.google.com/file/d/0B1lqZhpyr-KQZDliUm5Bc3dwQkE/view?usp=sharing

60
i don't have access to the machine until Monday, but do you think I can create a "fake shutdown.exe" to track the process that's trying to call it. Thanks for your help BTW, I'll try what you said when I get to work on Monday.
A year and a half ago another computer did the same thing. It also made the partition hidden on every restart.

61
 Some malware(?) calls shutdown.exe to restart the computer every three minutes, unless I use safe mode. In safe mode I can see the log in event viewer that says that shutdown.exe is doing this. I  renamed shutdown.exe and now the whole process "fails". In the sense that shutdown.exe doesn't get run and the computer stays on. The question is how can I track the process that's going this. Can I program some kind of a trace routing that would catch the culprit.
I tried naming notepad into shutdown.exe and see what happens but I get nothing.

62
it's not bad sectors nor the filesystem. I've check both. How would I fix permissions? I can't run tweakingtool in an offline mode, right?

63
I get a black screen with a mouse cursor when I try to boot. Ctrl+alt+del, doesn't work. When I try to run dism /cleanup-image it throws an error. The dism.log on the google drive is linked here.

https://drive.google.com/file/d/0B1lqZhpyr-KQQ1F2N1hlRFFNUEU/view?usp=sharing

64
ok I found the solution. You have to force the OS to check the volume before it mounts it.

http://www.retosphere.de/tipsandtricks/ntfserror.php

65
the problem is from the filesystem. It does the same when you pull the HDD and connect it to another machine.

66
Hi

A volume on the HDD pulled from a computer causes the computers to crash when you connect it to them. the error is

"paged fault in a non-paged area ntfs.sys "
I can't fix the filesystem, because connecting it causes a BSOD to the host's OS. have any idea how I can get around this?

P.S. The HDD doesn't do this in Linux or Mac. Obviously I can just copy the files in Linux/Mac and then redo the OS. But I want to preserve the OS, if possible

67
ok, the new profile works. how do I transfer everything from the old to the new. I want to keep the app settings also, not just the files in the user folders. I've heard about xcopy deployment, but don't know much about it.

68
Hi

I can't save or open files through Internet Explorer, can't see any start menu items (unless I click on all programs), can't pin or see pinned items in the taskbar (only the opened ones)

69
ok. Windows Search was deselected in Programs and Features. I also fixed the Windows Store not opening by using "Repair Windows 8 App Store"

70
Whats the regsvr32.exe command to register windows search?

71
OK, I did that already and it still doesn't show up in the services.msc. I tried to attach the entire services tree, but the file is 4MB and the forum says that its too big

72
The Windows search service is not running and is actually missing from the services.msc list. I created a backup of the entire HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search "tree" and is attached here. I think some subentries from that tree are missing.
Also Windows Store doesn't start up, I don't know if this is related or not.

73
General Computer Support / Re: system has recovered from a serious error
« on: January 21, 2015, 12:23:59 pm »
since I'm running XP, the program says it needs an extra component and then freezes. BTW. When I tried to uninstall AVG, it said that the installer service is not started. Is that any indication of something?

74
General Computer Support / Re: system has recovered from a serious error
« on: January 20, 2015, 01:54:51 pm »
i am attaching the dump file too

75
General Computer Support / system has recovered from a serious error
« on: January 20, 2015, 01:51:42 pm »
a virus, I think the name was serif, disabled my internet. I ran the all in one repair tool and it fixed it. Now, I keep getting a the "system has recovered from a serious" error, even if I click "don't send" it comes up again.


Pages: 1 2 [3] 4