Windows 11 Home Not Working After Windows Tweaking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by beckylousiana, Jul 9, 2025.

  1. beckylousiana

    beckylousiana Corporal

    Rebooted without the Recovery USB, finally Found 2 files under X: drive 1.) OfflineRecEnvTrace.etl and a 2.) OfflineStartupRepairTrace.etl in notepad- Here is the LINK for both of those files: https://gofile.io/d/3eWIm7

    ____________________
    Yes, there are files in the folder C:\FRST\HIVES -
    -components
    -default
    -sam
    -security
    -software
    -system

    ______________

    LINK to “SYSTEM” file found in C:\Windows\Sysem32\config - https://gofile.io/d/04R3n8

    ______________

    FRST scan results explorer.exe.User32.dll;InputHost.dll -Link and copied and pasted below https://gofile.io/d/8AQ8sy
    Farbar Recovery Scan Tool (x64) Version: 31-07-2025
    Ran by SYSTEM (01-07-2025 11:28:35)
    Running from E:\
    Boot Mode: Recovery
    ================== Search Files: "explorer.exe;User32.dll;InputHost.dll" =============
    C:\Windows\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 002943472 _____ (Microsoft Corporation) 4B45E7EFC0828E12F4AA66EE872D1599
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4343_none_735d884251b88c93\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001876512 _____ (Microsoft Corporation) 5B51C9F17524B5E74C90AE1700A52497
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4343_none_735d884251b88c93\r\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 000177818 _____ () 8E6D683C339AC1B015570A91A03E3E51
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4061_none_7380262a519e382c\user32.dll
    [2025-06-09 18:30][2025-06-09 18:30] 001870808 _____ (Microsoft Corporation) 6ABCE7742AD1CB67696BBD8376D2F741
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4061_none_7380262a519e382c\r\user32.dll
    [2025-06-09 18:30][2025-06-09 18:30] 000181430 _____ () C826FBB29AD4528737141729B0624765
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3775_none_733519fa51d67e77\user32.dll
    [2025-04-08 17:14][2025-04-08 17:14] 001861536 _____ (Microsoft Corporation) 908A82BC19174CEA1928EF11907136D8
    C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3775_none_733519fa51d67e77\r\user32.dll
    [2025-04-08 17:14][2025-04-08 17:14] 000173610 _____ () DF09B215A0CDF33830FB6FAC5A54F3BD
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4202_none_430be3290ee52def\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001510824 _____ (Microsoft Corporation) 2759417788CA7A4ECCE7E35528402129
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4202_none_430be3290ee52def\r\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 000380620 _____ () 085034B05F0BEC686586F1A89B8DB587
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4061_none_43279b850ecf7476\InputHost.dll
    [2025-06-09 18:30][2025-06-09 18:30] 001508808 _____ (Microsoft Corporation) EED31834A2BAC3C8A60357E797FC7051
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4061_none_43279b850ecf7476\r\InputHost.dll
    [2025-06-09 18:30][2025-06-09 18:30] 000362788 _____ () 9B96B4D085FE20F7EA8CF6DAB3EFF644
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.3624_none_42e274970f04067c\InputHost.dll
    [2025-03-27 19:25][2025-03-27 19:25] 001505672 _____ (Microsoft Corporation) 2AE7970AEC5165571DC0C60C407672CE
    C:\Windows\WinSxS\wow64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.3624_none_42e274970f04067c\r\InputHost.dll
    [2025-03-27 19:25][2025-03-27 19:25] 000362062 _____ () 17454868991A3239B8E0315A395DB347
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4202_none_f7e0a89f5e13e132\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 002600120 _____ (Microsoft Corporation) 9CA64388DC96728FBE71F312CF40BFA6
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4202_none_f7e0a89f5e13e132\r\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 000472984 _____ () DDE7D7F6B4A7984445CDB42F6317D489
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4061_none_f7fc60fb5dfe27b9\explorer.exe
    [2025-06-09 18:30][2025-06-09 18:30] 002587224 _____ (Microsoft Corporation) 91640C9C4AB36A3854BB86E2CB7FF7BA
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4061_none_f7fc60fb5dfe27b9\r\explorer.exe
    [2025-06-09 18:30][2025-06-09 18:30] 000460087 _____ () F70C64B9357D585E15B0E2E811919567
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.3624_none_f7b73a0d5e32b9bf\explorer.exe
    [2025-03-27 19:24][2025-03-27 19:24] 002535040 _____ (Microsoft Corporation) 77911A24729DB6484AEC8F2AB31E5D66
    C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.3624_none_f7b73a0d5e32b9bf\r\explorer.exe
    [2025-03-27 19:24][2025-03-27 19:24] 000427927 _____ () 4D4E7AAA39E8451E208A8AE8D705A5AE
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4202_none_690fc37c1d532faa\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001893952 _____ (Microsoft Corporation) 154F460D463CC2F26C05131CCAE47811
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.4202_none_690fc37c1d532faa\r\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 000214352 _____ () 8C2CD7FD05F293BA0698FD33A7F717BE
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3912_none_68c5126c1d8b0f71\user32.dll
    [2025-06-09 18:30][2025-06-09 18:30] 001893936 _____ (Microsoft Corporation) 01933E41CE681D752B28BA8F4665B562
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3912_none_68c5126c1d8b0f71\r\user32.dll
    [2025-06-09 18:30][2025-06-09 18:30] 000210118 _____ () 8FB0015BEBA0534C173862ED495CD14C
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3775_none_68e06fa81d75bc7c\user32.dll
    [2025-04-08 17:14][2025-04-08 17:14] 001902200 _____ (Microsoft Corporation) 57131119F6FA6A8E736BDAF0A452A0AF
    C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.3775_none_68e06fa81d75bc7c\r\user32.dll
    [2025-04-08 17:14][2025-04-08 17:14] 000191855 _____ () 7CF73EBADC0F940E39BFD130F69983F4
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4202_none_38b738d6da846bf4\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001988960 _____ (Microsoft Corporation) 4D569544EFF4302A803372FF02D8BFA4
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4202_none_38b738d6da846bf4\r\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 000429469 _____ () F27905032CA646BFDB4D77357C2C9372
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4061_none_38d2f132da6eb27b\InputHost.dll
    [2025-06-09 18:30][2025-06-09 18:30] 001989000 _____ (Microsoft Corporation) B6FDAEEAB21ABC30A760C2C591816B0B
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.4061_none_38d2f132da6eb27b\r\InputHost.dll
    [2025-06-09 18:30][2025-06-09 18:30] 000393077 _____ () EDF118D18C51F46F1750C96B816F4B75
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.3624_none_388dca44daa34481\InputHost.dll
    [2025-03-27 19:25][2025-03-27 19:25] 001984840 _____ (Microsoft Corporation) 8E1E50A791388405EA8DE2B934E5C067
    C:\Windows\WinSxS\amd64_microsoft-windows-onecore-inputhost_31bf3856ad364e35_10.0.26100.3624_none_388dca44daa34481\r\InputHost.dll
    [2025-03-27 19:25][2025-03-27 19:25] 000377706 _____ () 49A07936999A900C2A4F073084A321F3
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4202_none_ed8bfe4d29b31f37\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 002943472 _____ (Microsoft Corporation) 4B45E7EFC0828E12F4AA66EE872D1599
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4202_none_ed8bfe4d29b31f37\r\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 000607497 _____ () EEFD5FE0E6DF727D9F6A2C56CD1E9992
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4061_none_eda7b6a9299d65be\explorer.exe
    [2025-06-09 18:30][2025-06-09 18:30] 002926936 _____ (Microsoft Corporation) 6F73474742CBDAFCDA0F4E1834473B4E
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.4061_none_eda7b6a9299d65be\r\explorer.exe
    [2025-06-09 18:30][2025-06-09 18:30] 000597058 _____ () 2D0A5D4BD551858F51180733EC4F215C
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.3624_none_ed628fbb29d1f7c4\explorer.exe
    [2025-03-27 19:24][2025-03-27 19:24] 002856720 _____ (Microsoft Corporation) 3C8DED08108CB98D4A721EBD98EDF610
    C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.26100.3624_none_ed628fbb29d1f7c4\r\explorer.exe
    [2025-03-27 19:24][2025-03-27 19:24] 000454143 _____ () C496CE7F09100041057661BE650690A4
    C:\Windows\SysWOW64\explorer.exe
    [2025-06-11 16:22][2025-06-11 16:22] 002600120 _____ (Microsoft Corporation) 9CA64388DC96728FBE71F312CF40BFA6
    C:\Windows\SysWOW64\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001510824 _____ (Microsoft Corporation) 2759417788CA7A4ECCE7E35528402129
    C:\Windows\SysWOW64\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001876512 _____ (Microsoft Corporation) 5B51C9F17524B5E74C90AE1700A52497
    C:\Windows\System32\InputHost.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001988960 _____ (Microsoft Corporation) 4D569544EFF4302A803372FF02D8BFA4
    C:\Windows\System32\user32.dll
    [2025-06-11 16:22][2025-06-11 16:22] 001893952 _____ (Microsoft Corporation) 154F460D463CC2F26C05131CCAE47811
    X:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.26100.1_none_ca2c14a1d5e919b7\user32.dll
    [2024-03-31 23:38][2024-03-31 23:38] 001852616 _____ (Microsoft Corporation) 5085AC1CE2A5D235E47357DB542AD6AC
    X:\Windows\System32\user32.dll
    [2024-03-31 23:38][2024-03-31 23:38] 001852616 _____ (Microsoft Corporation) 5085AC1CE2A5D235E47357DB542AD6AC
    ====== End of Search ======
     
  2. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your work and all of the information.

    We previously attempted to replace the system file contained in the C:\Windows\System32\Config folder. I had you provide the system file again on a hunch there still might be a problem with it. As it turns out there was a problem and hopefully this new version will help us out.

    Please do this.

    • Download System.zip to your Desktop
    • Unzip the folder onto the Desktop
    • Copy and paste the System file onto your USB
    • Repeat the previous process you used to navigate to C:\Windows\System32\Config\System
    • Right click on System, select Rename, and rename it to Systemold8-7-25
    • Copy and paste the System file located on the USB into the C:\Windows\System32\Config folder
    • Shut down your computer
    • Start your computer and attempt to boot into Windows
    ===================================================

    Things I would like to see in your next reply.
    • Results?
     
  3. beckylousiana

    beckylousiana Corporal

    Got the system file in the folder :)
    The computer booted to Bitlocker key blue screen > your device ran into a problem > rebooted itself and opened back up into bitlocker again, preparing automatic repair, BitLocker key to enter "to get going again", continue, diagnosing your pc, Automatic Repair, Your PC did noy start correctly, Restart or Advanced options
     
  4. Oh My!

    Oh My! Malware Expert Staff Member

    Please run a new FRST scan, I want to see what changes have been made, if any, since the last scan.

    Download the attached file onto the USB containing FRST64. Launch FRST64, click Fix and a Fixlog.txt will be placed on the USB drive. Copy and paste the report in your reply.
     
  5. beckylousiana

    beckylousiana Corporal

    I
    Was there supposed to be a file attached?
     
  6. Oh My!

    Oh My! Malware Expert Staff Member

    That would be helpful.

    I woke up in the middle of the night realizing I didn't attach it. :)
     

    Attached Files:

    beckylousiana likes this.
  7. beckylousiana

    beckylousiana Corporal

    LOL!! I appreciate your efforts and sticking with me on this!
    Here is the FixLog txt -
    Fix result of Farbar Recovery Scan Tool (x64) Version: 31-07-2025
    Ran by SYSTEM (02-07-2025 11:01:18) Run:1
    Running from E:\
    Boot Mode: Recovery
    ==============================================
    fixlist content:
    *****************
    Folder: C:\FRST
    cmd: chkdsk C:
    *****************
    ========================= Folder: C:\FRST ========================
    2024-04-18 23:49 - 2024-04-18 23:49 - 000000000 ____D [00000000000000000000000000000000] () C:\FRST\bin
    2019-11-06 02:16 - 2019-11-06 02:16 - 001077248 ____A [AEB9555DA8A72977775C109E69843F2B] (SQLite Development Team) C:\FRST\bin\sqlite3_x64.dll
    2025-07-01 11:22 - 2025-07-01 11:22 - 000000000 ____D [00000000000000000000000000000000] () C:\FRST\Hives
    2025-07-01 11:22 - 2025-04-07 11:11 - 049750016 ____A [68C578FA8B332C46BF93C2F1E918BFFA] () C:\FRST\Hives\components
    2025-07-01 11:22 - 2025-04-07 11:11 - 001835008 ____A [3E8F85EB4B167E4F148C96405FA2E874] () C:\FRST\Hives\default
    2025-07-01 11:22 - 2025-06-24 12:15 - 000065536 ____A [A7F25AC9BE21F7FE5C41F048E62C6D0B] () C:\FRST\Hives\sam
    2025-07-01 11:22 - 2025-06-24 12:15 - 000040960 ____A [FF651D90B2E47B1FCB52E052E68655B1] () C:\FRST\Hives\security
    2025-07-01 11:22 - 2025-06-27 16:12 - 000262144 ____A [C2B074595905562566B4AB46A745FAA5] () C:\FRST\Hives\software
    2025-07-01 11:22 - 2025-07-30 13:05 - 027947008 ____A [D9C57C60CF1A294DF5470636FCD46802] () C:\FRST\Hives\System
    2024-04-18 23:49 - 2024-04-18 23:49 - 000000000 ____D [00000000000000000000000000000000] () C:\FRST\Hives\Old
    2024-04-18 23:49 - 2025-04-07 11:11 - 049750016 ____A [68C578FA8B332C46BF93C2F1E918BFFA] () C:\FRST\Hives\Old\components
    2024-04-18 23:49 - 2025-04-07 11:11 - 001835008 ____A [3E8F85EB4B167E4F148C96405FA2E874] () C:\FRST\Hives\Old\default
    2024-04-18 23:49 - 2025-06-24 12:15 - 000065536 ____A [A7F25AC9BE21F7FE5C41F048E62C6D0B] () C:\FRST\Hives\Old\sam
    2024-04-18 23:49 - 2025-06-24 12:15 - 000040960 ____A [FF651D90B2E47B1FCB52E052E68655B1] () C:\FRST\Hives\Old\security
    2024-04-18 23:49 - 2024-04-12 21:23 - 000262144 ____A [64A78D59ADE6B29A9A0D3E7AC99C79CC] () C:\FRST\Hives\Old\software
    2024-04-18 23:49 - 2025-06-24 08:25 - 027947008 ____A [FA9102301464A48D527337425C897722] () C:\FRST\Hives\Old\system
    2024-04-18 23:49 - 2024-04-18 23:50 - 000000000 ____D [00000000000000000000000000000000] () C:\FRST\Logs
    2024-04-18 23:49 - 2025-07-02 11:01 - 000000013 __ASH [BAB4D1FE7CE6885F3D29ABF8BE3E2C19] () C:\FRST\Logs\ct.ini
    2024-04-18 23:50 - 2024-04-18 23:50 - 000885645 ____A [EA54DBC719CBA619E97AEA5149DDE7D3] () C:\FRST\Logs\FRST_18-04-2024 23.50.00.txt
    2024-04-18 23:49 - 2024-04-18 23:49 - 000000000 ____D [00000000000000000000000000000000] () C:\FRST\Quarantine
    ====== End of Folder: ======
    ========= chkdsk C: =========
    The type of the file system is NTFS.
    The specified object was not found.
    The volume is in use by another process. Chkdsk
    might report errors when no corruption is present.
    Volume label is OS.
    WARNING! /F parameter not specified.
    Running CHKDSK in read-only mode.
    Stage 1: Examining basic file system structure ...
    Progress: 0 of 1388032 done; Stage: 0%; Total: 0%; ETA: 1:06:44
    Progress: 21761 of 1388032 done; Stage: 1%; Total: 0%; ETA: 1:06:22 .
    Progress: 56577 of 1388032 done; Stage: 4%; Total: 1%; ETA: 1:05:48 ..
    Progress: 97025 of 1388032 done; Stage: 6%; Total: 2%; ETA: 0:00:52 ...
    Progress: 134587 of 1388032 done; Stage: 9%; Total: 3%; ETA: 0:00:52
    Progress: 173393 of 1388032 done; Stage: 12%; Total: 4%; ETA: 0:00:51 .
    Progress: 203265 of 1388032 done; Stage: 14%; Total: 5%; ETA: 0:00:51 ..
    Progress: 230321 of 1388032 done; Stage: 16%; Total: 5%; ETA: 0:00:52 ...
    Progress: 289032 of 1388032 done; Stage: 20%; Total: 7%; ETA: 0:00:44
    Progress: 352425 of 1388032 done; Stage: 25%; Total: 9%; ETA: 0:00:40 .
    Progress: 431361 of 1388032 done; Stage: 31%; Total: 11%; ETA: 0:00:36 ..
    Progress: 506682 of 1388032 done; Stage: 36%; Total: 13%; ETA: 0:00:35 ...
    Progress: 536383 of 1388032 done; Stage: 38%; Total: 14%; ETA: 0:00:35
    Progress: 561862 of 1388032 done; Stage: 40%; Total: 14%; ETA: 0:00:35 .
    Progress: 595457 of 1388032 done; Stage: 42%; Total: 15%; ETA: 0:00:36 ..
    Progress: 623873 of 1388032 done; Stage: 44%; Total: 16%; ETA: 0:00:36 ...
    Progress: 701734 of 1388032 done; Stage: 50%; Total: 18%; ETA: 0:00:35
    Progress: 785665 of 1388032 done; Stage: 56%; Total: 20%; ETA: 0:00:33 .
    Progress: 889089 of 1388032 done; Stage: 64%; Total: 23%; ETA: 0:00:30 ..
    Progress: 984321 of 1388032 done; Stage: 70%; Total: 25%; ETA: 0:00:28 ...
    Progress: 1071361 of 1388032 done; Stage: 77%; Total: 27%; ETA: 0:00:27
    Progress: 1174273 of 1388032 done; Stage: 84%; Total: 29%; ETA: 0:00:25 .
    Progress: 1306775 of 1388032 done; Stage: 94%; Total: 33%; ETA: 0:00:22 ..
    Progress: 1358337 of 1388032 done; Stage: 97%; Total: 34%; ETA: 0:00:22 ...
    Progress: 1388032 of 1388032 done; Stage: 100%; Total: 34%; ETA: 0:00:22


    1388032 file records processed.
    File verification completed.
    Phase duration (File record verification): 11.44 seconds.
    Progress: 24963 of 24963 done; Stage: 100%; Total: 30%; ETA: 0:00:25 .


    24963 large file records processed.
    Phase duration (Orphan file record recovery): 7.02 milliseconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 30%; ETA: 0:00:25 ..


    0 bad file records processed.
    Phase duration (Bad file record checking): 0.01 milliseconds.
    Stage 2: Examining file name linkage ...
    Progress: 108503 of 1796090 done; Stage: 6%; Total: 32%; ETA: 0:00:25 ...
    Progress: 285758 of 1796090 done; Stage: 15%; Total: 36%; ETA: 0:00:22
    Progress: 517493 of 1796090 done; Stage: 28%; Total: 41%; ETA: 0:00:19 .
    Progress: 845200 of 1796090 done; Stage: 47%; Total: 48%; ETA: 0:00:14 ..
    Progress: 1388035 of 1796090 done; Stage: 77%; Total: 60%; ETA: 0:00:09 ...
    Progress: 10297 of 10297 done; Stage: 100%; Total: 60%; ETA: 0:00:09


    10297 reparse records processed.
    Progress: 1391747 of 1796090 done; Stage: 77%; Total: 61%; ETA: 0:00:09 .
    Progress: 1394596 of 1796090 done; Stage: 77%; Total: 61%; ETA: 0:00:09 ..
    Progress: 1400458 of 1796090 done; Stage: 77%; Total: 62%; ETA: 0:00:09 ...
    Progress: 1414932 of 1796090 done; Stage: 78%; Total: 63%; ETA: 0:00:09
    Progress: 1423325 of 1796090 done; Stage: 79%; Total: 64%; ETA: 0:00:09 .
    Progress: 1431911 of 1796090 done; Stage: 79%; Total: 64%; ETA: 0:00:09 ..
    Progress: 1441106 of 1796090 done; Stage: 80%; Total: 65%; ETA: 0:00:09 ...
    Progress: 1445135 of 1796090 done; Stage: 80%; Total: 66%; ETA: 0:00:09
    Progress: 1450792 of 1796090 done; Stage: 80%; Total: 67%; ETA: 0:00:09 .
    Progress: 1457983 of 1796090 done; Stage: 81%; Total: 68%; ETA: 0:00:09 ..
    Progress: 1477749 of 1796090 done; Stage: 82%; Total: 69%; ETA: 0:00:09 ...
    Progress: 1484811 of 1796090 done; Stage: 82%; Total: 70%; ETA: 0:00:09
    Progress: 1492418 of 1796090 done; Stage: 83%; Total: 70%; ETA: 0:00:09 .
    Progress: 1503021 of 1796090 done; Stage: 83%; Total: 70%; ETA: 0:00:09 ..
    Progress: 1520159 of 1796090 done; Stage: 84%; Total: 71%; ETA: 0:00:09 ...
    Progress: 1534727 of 1796090 done; Stage: 85%; Total: 72%; ETA: 0:00:09
    Progress: 1552866 of 1796090 done; Stage: 86%; Total: 72%; ETA: 0:00:09 .
    Progress: 1572249 of 1796090 done; Stage: 87%; Total: 73%; ETA: 0:00:09 ..
    Progress: 1582012 of 1796090 done; Stage: 88%; Total: 75%; ETA: 0:00:07 ...
    Progress: 1796090 of 1796090 done; Stage: 100%; Total: 76%; ETA: 0:00:07


    1796090 index entries processed.
    Index verification completed.
    Phase duration (Index verification): 12.30 seconds.
    Progress: 1 of 0 done; Stage: 99%; Total: 76%; ETA: 0:00:07 .
    Progress: 0 of 0 done; Stage: 99%; Total: 76%; ETA: 0:00:07 ..


    0 unindexed files scanned.
    Phase duration (Orphan reconnection): 1.19 seconds.
    Progress: 0 of 0 done; Stage: 99%; Total: 76%; ETA: 0:00:07 ...


    0 unindexed files recovered to lost and found.
    Phase duration (Orphan recovery to lost and found): 0.01 milliseconds.
    Progress: 10297 of 10297 done; Stage: 100%; Total: 76%; ETA: 0:00:07


    10297 reparse records processed.
    Phase duration (Reparse point and Object ID verification): 19.54 milliseconds.
    Stage 3: Examining security descriptors ...
    Security descriptor verification completed.
    Phase duration (Security descriptor verification): 17.13 milliseconds.
    Progress: 24 of 24 done; Stage: 100%; Total: 99%; ETA: 0:00:00 .


    204030 data files processed.
    Phase duration (Data attribute verification): 0.02 milliseconds.
    CHKDSK is verifying Usn Journal...
    Progress: 240 of 240 done; Stage: 100%; Total: 99%; ETA: 0:00:00 ..


    1966712 USN bytes processed.
    Usn Journal verification completed.
    Phase duration (USN journal verification): 10.58 milliseconds.
    Windows has scanned the file system and found no problems.
    No further action is required.
    498594119 KB total disk space.
    216602116 KB in 252676 files.
    273728 KB in 204031 indexes.
    0 KB in bad sectors.
    1487971 KB in use by the system.
    65536 KB occupied by the log file.
    280230304 KB available on disk.
    4096 bytes in each allocation unit.
    124648529 total allocation units on disk.
    70057576 allocation units available on disk.
    Total duration: 24.99 seconds (24999 ms).
    Unable to obtain a handle to the event log.
    ========= End of CMD: =========
    ==== End of Fixlog 11:01:46 ====
     
  8. Oh My!

    Oh My! Malware Expert Staff Member

    In case you overlooked it, could you run another FRST scan?
     
  9. beckylousiana

    beckylousiana Corporal

  10. Oh My!

    Oh My! Malware Expert Staff Member

    Before we make any changes I would like you to attempt to boot into Safe Mode with Command Prompt. You may have to enter the BitLocker Key.

    • Attempt to boot your computer
    • Select Advanced options
    • Select Troubleshoot
    • Select Advanced options
    • Select Startup Settings
    • Select Restart
    • Press 6) to Enable Safe Mode with Command Prompt
    • Let me know what happens and if any specific error information appears
     
  11. beckylousiana

    beckylousiana Corporal

    After choosing Startup Settings - Restart - Enter the recovery key for this drive - Your device ran into a problem and needs to restart, We'll restart it for you, then computer goes off.

    restarted: Enter the recovery key to get going again - Diagnosing your computer - Your computer did not start correctly - Advanced options - troubleshoot - Advanced Options - Startup Settings - Diagnosing your PC - Startup Repair Couldn't repair your PC - Advanced Options - Troubleshoot - Advanced Options - Startup Settings - restart - BitLocker you must enter your recovery key to access Startup Settings, press enter to continue - Enter the recovery key for this drive - 6.) Enable Safe Mod with Command Prompt - computer restarts - Automatic Repair Your computer did not start correctly - Advanced Options - BitLocker Recovery key then computer dies within 60 seconds before I enter the key.


    -- Repeated steps above but was able to enter recovery key before the pc went off - advanced options - troubleshoot - Advanced options - startup settings - restart - BitLocker you must enter your recovery key to access Startup Settings - Enable Safe Mode with Command Prompt - Your device ran into a prob---- BitLocker Key - Preparing Automatic Repair - Automatic Repair your PC did no start correctly - Advanced Options - Troubleshoot - Advanced Options - startup settings - restart - BitLocker entry recovery - Startup Settings - Your device ran into a problem..... Enter the recovery Key for this drive - Preparing Automatic Repair - BiltLocker enter the recovery key to get going again - Diagnosing your PC - Automatic Repair, Your PC did not start correctly - Advanced options -
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    Boy you sure gave it a good try.

    I am assuming the USB drive letter is still E:. If not, part of the Fixlist will not work.

    Please do this.

    • Download the attached file and save it to the USB containing FRST64.exe
    • Attach the USB to the compromised computer
    • Navigate to the computer Recovery Environment Command Prompt
    • Type sfc /scannow /offbootdir=c:\ /offwindir=c:\windows
    • Report the results in your reply
    • Navigate to and launch FRST64
    • Click Fix and allow the process to complete
    • Shut down the computer
    • Restart the computer and attempt to boot it Normally or Safe Boot
    • Copy and paste the contents of the Fixlog.txt report from your USB device
    • If there is a DUMP2470.tmp and C:\Windows\ntbtlog.txt file on the USB device upload them to GoFile and provide the download link
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Results of sfc /scannow?
    • Fixlog.txt
    • Computer able to boot?
    • Download links
     

    Attached Files:

  13. beckylousiana

    beckylousiana Corporal

    Just letting you know that I am still working on it. We have been so busy i have not been able to complete your last instruction, but I will today!! ❤️
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    No problem. Thanks for the update.
     
  15. beckylousiana

    beckylousiana Corporal

    The USB is E in the working computer, but when I plug it into the broken computer it shows as F.
    Actually there is only 1 removeable device in the broken computer, but it shows 2 -
    See attached and cmd results Below:

    Microsoft Windows [Version 10.0.26100.1]
    (c) Microsoft Corporation. All rights reserved.
    X:\Windows\System32>sfc /scannow /offbootdir=c\ /offwindir=c\windows
    Windows Resource Protection could not start the repair service.
    X:\Windows\System32>diskpart
    Microsoft DiskPart version 10.0.26100.1
    Copyright (C) Microsoft Corporation.
    On computer: MININT-76O6K7E
    DISKPART> list vol
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    Volume 0 C OS NTFS Partition 475 GB Healthy
    Volume 1 SYSTEM FAT32 Partition 260 MB Healthy Hidden
    Volume 2 D RECOVERY NTFS Partition 1000 MB Healthy Hidden
    Volume 3 MYASUS FAT32 Partition 200 MB Healthy Hidden
    Volume 4 E UUI exFAT Removable 58 GB Healthy
    Volume 5 F VTOYEFI FAT Removable 32 MB Healthy
    DISKPART> list disk
    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 476 GB 0 B *
    Disk 1 Online 58 GB 0 B
    DISKPART>
     

    Attached Files:

  16. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for letting me know.

    I modified the Fixlist.txt file to reflect the change in Drive letter. You can run the instructions and see how we do.
     
    beckylousiana likes this.
  17. beckylousiana

    beckylousiana Corporal

    do i need to download a different Fixlist.txt file?
     
  18. Oh My!

    Oh My! Malware Expert Staff Member

    Delete the previous Fixlist. Click on the Fixlist.txt file attached to Post #212. It is the newly modified one reflecting the correct drive letter for 2 of the commands in the Fixlist.
     
    beckylousiana likes this.
  19. beckylousiana

    beckylousiana Corporal

    Could not boot into safe mode or safe mode with command prompt :(

    Link to ntblog & results of cmd scan - https://gofile.io/d/DTIlHz

    FIX log:
    Fix result of Farbar Recovery Scan Tool (x64) Version: 11-08-2025
    Ran by SYSTEM (07-07-2025 21:14:28) Run:2
    Running from F:\
    Boot Mode: Recovery
    ==============================================
    fixlist content:
    *****************
    Copy: C:\DUMP2470.tmp F:\
    Copy: C:\Windows\ntbtlog.txt F:\
    HKLM\...\.exe: => <==== ATTENTION
    HKLM\...\exefile\DefaultIcon: <==== ATTENTION
    HKLM\...\exefile\shell\open\command: <==== ATTENTION
    HKLM\...\Winlogon: [Userinit] <==== ATTENTION
    HKLM\...\Winlogon: [Shell] <=== ATTENTION
    HKLM-x32\...\Winlogon: [Shell] <=== ATTENTION
    HKLM\.. .\InprocServer32: [Default-wbemess] <==== ATTENTION
    HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] <==== ATTENTION
    HKU\ltfro\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ltfro\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
    HKU\ltfro\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\ltfro\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
    HKU\ltfro\...\RunOnce: [Uninstall 25.020.0202.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ltfro\AppData\Local\Microsoft\OneDrive\25.020.0202.0001" (No File)
    StartupCommonDir: <==== ATTENTION
    StartupCommonDirx86: <==== ATTENTION
    S3 aswBcc; no ImagePath
    S3 Avast Business Console Client Antivirus Service; no ImagePath
    S3 avast! Firewall; no ImagePath
    UpperFilters: [{4D36E967-E325-11CE-BFC1-08002BE10318}] -> [partmgr aswArDisk]
    UpperFilters: [{4D36E96B-E325-11CE-BFC1-08002BE10318}] -> [aswKbd kbdclass]
    2025-07-01 10:49 - 2025-07-01 10:49 - 000000000 ____D C:\New folder (2)
    2025-07-01 10:49 - 2025-07-01 10:49 - 000000000 ____D C:\New folder
    2025-06-27 13:10 - 2025-06-27 13:13 - 178906920 _____ C:\DUMP24fd.tmp
    2025-06-27 13:09 - 2025-06-27 13:10 - 178906664 _____ C:\DUMP2589.tmp
    2025-06-27 13:06 - 2025-06-27 13:09 - 178900536 _____ C:\DUMP24ce.tmp
    2025-06-27 12:31 - 2025-06-27 12:31 - 000000000 ____D C:\found.000
    2025-06-27 09:36 - 2025-06-27 13:06 - 178896824 _____ C:\DUMP24cd.tmp
    2025-06-27 09:29 - 2025-06-27 09:36 - 178893248 _____ C:\DUMP1b48.tmp
    2025-06-27 07:22 - 2025-06-27 09:29 - 178901544 _____ C:\DUMP2490.tmp
    2025-06-27 06:42 - 2025-06-27 07:22 - 178901408 _____ C:\DUMP247f.tmp
    2025-06-26 15:03 - 2025-06-27 06:42 - 178897648 _____ C:\DUMP24fc.tmp
    2025-06-26 15:00 - 2025-06-26 15:03 - 178901072 _____ C:\DUMP1c52.tmp
    2025-06-24 11:41 - 2025-06-26 15:00 - 178903608 _____ C:\DUMP2616.tmp
    2025-06-24 11:05 - 2025-06-24 11:41 - 178901672 _____ C:\DUMP24dd.tmp
    2025-06-24 10:55 - 2025-06-24 11:05 - 178901336 _____ C:\DUMP0dfa.tmp
    2025-06-24 10:42 - 2025-06-24 10:55 - 178904816 _____ C:\DUMP24bf.tmp
    2025-06-24 10:37 - 2025-06-24 10:42 - 178901456 _____ C:\DUMP0ffd.tmp
    2025-06-24 10:26 - 2025-06-24 10:37 - 178902888 _____ C:\DUMP2460.tmp
    2025-06-24 10:24 - 2025-06-24 10:26 - 178906800 _____ C:\DUMP251c.tmp
    2025-06-24 10:24 - 2025-06-24 10:24 - 178904752 _____ C:\DUMP249f.tmp
    2025-06-24 10:09 - 2025-06-24 10:24 - 178902792 _____ C:\DUMP24be.tmp
    2025-06-24 10:08 - 2025-06-24 10:09 - 178903976 _____ C:\DUMP248f.tmp
    2025-06-24 10:00 - 2025-06-24 10:08 - 178901168 _____ C:\DUMP24ae.tmp
    *****************
    ================== "Copy: C:\DUMP2470.tmp F:\" ===================
    "C:\DUMP2470.tmp" => Could not copy (Error:112)
    === End of Copy: ===
    ================== "Copy: C:\Windows\ntbtlog.txt F:\" ===================
    "C:\Windows\ntbtlog.txt" copied successfully
    === End of Copy: ===
    HKLM\Software\Classes\.exe\\"Default"="exefile" => value restored successfully
    HKLM\Software\Classes\exefile\DefaultIcon\\"Default"="%1" => value restored successfully
    HKLM\Software\Classes\exefile\shell\open\command\\"Default"=""%1" %*" => value restored successfully
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"="C:\WINDOWS\system32\userinit.exe," => value restored successfully
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"="Explorer.exe" => value restored successfully
    HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"="Explorer.exe" => value restored successfully
    HKLM\.. .\InprocServer32: [Default-wbemess] <==== ATTENTION => Error: No automatic fix found for this entry.
    HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\"Default"="%systemroot%\system32\wbem\fastprox.dll" => value restored successfully
    "HKU\ltfro\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Update Binary" => removed successfully
    "HKU\ltfro\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Delete Cached Standalone Update Binary" => removed successfully
    "HKU\ltfro\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall 25.020.0202.0001" => removed successfully
    StartupCommonDir: <==== ATTENTION => restored successfully
    StartupCommonDirx86: <==== ATTENTION => restored successfully
    HKLM\System\ControlSet001\Services\aswBcc => removed successfully
    aswBcc => service removed successfully
    HKLM\System\ControlSet001\Services\Avast Business Console Client Antivirus Service => removed successfully
    Avast Business Console Client Antivirus Service => service removed successfully
    HKLM\System\ControlSet001\Services\avast! Firewall => removed successfully
    avast! Firewall => service removed successfully
    HKLM\System\ControlSet001\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\\"UpperFilters"="PartMgr" => value restored successfully
    HKLM\System\ControlSet001\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\\"UpperFilters"="kbdclass" => value restored successfully
    C:\New folder (2) => Could not move
    C:\New folder => Could not move
    C:\DUMP24fd.tmp => moved successfully
    C:\DUMP2589.tmp => moved successfully
    C:\DUMP24ce.tmp => moved successfully
    C:\found.000 => Could not move
    C:\DUMP24cd.tmp => moved successfully
    C:\DUMP1b48.tmp => moved successfully
    C:\DUMP2490.tmp => moved successfully
    C:\DUMP247f.tmp => moved successfully
    C:\DUMP24fc.tmp => moved successfully
    C:\DUMP1c52.tmp => moved successfully
    C:\DUMP2616.tmp => moved successfully
    C:\DUMP24dd.tmp => moved successfully
    C:\DUMP0dfa.tmp => moved successfully
    C:\DUMP24bf.tmp => moved successfully
    C:\DUMP0ffd.tmp => moved successfully
    C:\DUMP2460.tmp => moved successfully
    C:\DUMP251c.tmp => moved successfully
    C:\DUMP249f.tmp => moved successfully
    C:\DUMP24be.tmp => moved successfully
    C:\DUMP248f.tmp => moved successfully
    C:\DUMP24ae.tmp => moved successfully
    ==== End of Fixlog 21:14:28 ====
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Launch FRST64.exe. Copy and paste SearchAll: Avast;Avira;wbemess in the Search: box then click Search Files. Attach the Search.txt file in your reply or, if too large, upload it and provide the download link.

    This most likely means there was not enough free space on the USB. Using your 64GB USB drive attempt to copy the C:\DUMP2470.tmp file onto it. If successful upload and provide the download link.

    Navigate to C:\Windows\Minidump. If there are files inside copy the Minidump folder attach the folder or upload it to Gofile and provide the download link.

    At the Recovery Environment command prompt type bcdedit /set {current} disableelamdrivers yes and hit Enter. Let me know if it was successful.

    At the Recovery Environment command prompt type sfc /scannow /offbootdir=c:\ /offwindir=c:\windows and hit Enter. Let me know what happens.

    At the Recovery Environment command prompt type mdsched and hit Enter. It may not work but let me know what happens.

    Attempt to boot your computer and if you are unable to do so run a new FRST64.exe scan.
     
  21. beckylousiana

    beckylousiana Corporal

    FINALLY I HOPE I have completed all your instructions. It has been crazy with travel so please let me know if I gave you everything you need. THANK YOUUUUU!!!

    Search.txt - https://gofile.io/d/cvHdWi


    C:\DUMP2470.tmp - https://gofile.io/d/n8QXMG


    I could not find folder C:\Windows\minidump


    Bcedot command - Operation completed successfully


    Sfc /scannow /offbootdir=c:\ - “Windows Resource Protection could not perform……


    Mdsched - ran successfully:


    Here is what my cmd looked like–

    Microsoft Windows [Version 10.0.26100.1]

    (c) Microsoft Corporation. All rights reserved.

    X:\Windows\System32>notepad

    X:\Windows\System32>bcdedit /set {current} disableelamdrivers yes

    The operation completed successfully.

    X:\Windows\System32>sfc /scannow /offbootdir=c:\ /offwindir=c:\windows

    Beginning system scan. This process will take some time.

    Windows Resource Protection could not perform the requested operation.

    X:\Windows\System32>mdsched

    X:\Windows\System32>


    Could not boot, ran FRST64 scan again and attached report -
    I am only using 64gb usb drives
    AGAIN my usb shows as F on my working computer but this time shows as D: on the compromised computer.... :/
     

    Attached Files:

  22. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the information.

    Hope something gives pretty soon, I am running out of ideas......

    Shut down the computer and disconnect it from all power sources, including removal of the battery, if possible.
    Hold down the power button for 30 seconds
    Attach power to the computer and attempt to boot.

    -----

    What, if anything, do you see before it gets to this windows. Does the computer go all the way through the POST process which includes the option to enter the BIOS, see the Windows or computer splash screen, etc? What do you see just prior to the Bitlocker page?

    -----

    Hidden within Post 162 was a request for you to attempt to locate and provide a C:\Window\System32\Logfiles\Srt\SrtTrail.txt report. I don't think we attempted that. Please see if that file is present and if so attach it to your reply.

    -----

    Boot using the USB
    Using the Notepad method locate the drive letter containing the Windows folder (C: or D: ).
    At the command prompt type DISM /image:C:\ /Get-Packages then hit Enter
    Provide any listed Packages information, if any appears

    -----

    Locate, copy and upload the C:\Windows\Logs\DISM and C:\Windows\Logs\CBS folders
     
  23. beckylousiana

    beckylousiana Corporal

    I want to thank you for all if your efforts!!
    Here are the results as I have been able to accomplish.

    I cannot remove the battery.

    I see a very very brief flash of the normal “ASUS In search of incredible” screen before it goes into BitLocker recover code

    I see that I missed the instruction, but I have found the file and attached it here. :)


    Upon booting to USB drive, Windows 11 setup - Language - Keyboard - Repair my PC - CHOOSE KEYBOARD - Choose an Option - Troubleshoot - Command Prompt - X:\sources> - notepad

    I could only locate Windows on X:\

    —---

    Command Prompt S:\sources>DISM /image:X

    :\ /Get-Packages

    Results:

    Microsoft Windows [Version 10.0.26100.4349]

    (c) Microsoft Corporation. All rights reserved.


    X:\sources>notepad


    X:\sources>DISM /image:X:\ /Get-Packages


    Deployment Image Servicing and Management tool

    Version: 10.0.26100.2454



    Error: 87


    The /Image option that is specified points to a running Windows installation.

    To service the running operating system, use the /Online option. For more information, refer to the help by running DISM.exe /Online /?.


    The DISM log file can be found at X:\windows\Logs\DISM\dism.log


    X:\sources>notepad


    X:\sources>

    ~~~~~~~~~~~~~~~~~


    There is a folder CBS but it is empty. even wuth ALL FILE TYPES being designated.
     

    Attached Files:

  24. Oh My!

    Oh My! Malware Expert Staff Member

    Please do this.

    • After booting to the USB while at the X:\sources prompt type C: and hit Enter
    • If it changes to the C:\> prompt type DISM /image:C:\ /Get-Packages then hit Enter
    • If information is populated click on the small command prompt icon in the top left corner of the larger window
    • Click Select All then hit Enter
    • Open Notepad, right click inside the window and click Paste
    • Copy and paste the contents of the report in your reply
     
  25. beckylousiana

    beckylousiana Corporal

    Microsoft Windows [Version 10.0.26100.4349]
    (c) Microsoft Corporation. All rights reserved.
    X:\sources>c:
    C:\>DISM /image:C:\ /Get-Packages
    Deployment Image Servicing and Management tool
    Version: 10.0.26100.1150
    Error: 2
    Unable to access the image.
    Make sure that the image path and the Windows directory for the image exist and you have Read permissions on the folder.
    The DISM log file can be found at X:\windows\Logs\DISM\dism.log
    C:\>
     

    Attached Files:

  26. Oh My!

    Oh My! Malware Expert Staff Member

    Please try these.

    Try to the same steps booting into the computer Recovery Environment. Let me know if it doesn't work even after providing the BitLocker Key.

    -----

    Enter the BIOS screen and navigate to "Reset to Default" or "Restore Defaults". Confirm the action. Save the changes then attempt to boot.

    -----

    • Attempt to boot your computer
    • Select Advanced options
    • Select Troubleshoot
    • Select Advanced options
    • Select Startup Settings
    • Select Restart
    • Press 7) to Disable driver signature enforcement
    • Let me know what happens and if any specific error information appears
     
  27. beckylousiana

    beckylousiana Corporal

    I rebooted with USB the same way, ran the Get-Packages and got the same results
    Microsoft Windows [Version 10.0.26100.4349]
    (c) Microsoft Corporation. All rights reserved.
    X:\sources>c:
    C:\>DISM /image:C:\ /Get-Packages
    Deployment Image Servicing and Management tool
    Version: 10.0.26100.1150
    Error: 2
    Unable to access the image.
    Make sure that the image path and the Windows directory for the image exist and you have Read permissions on the folder.
    The DISM log file can be found at X:\windows\Logs\DISM\dism.log
    C:\>

    Rebooted without USB, ran the Get-Packages instructions see results:

    Microsoft Windows [Version 10.0.26100.4349]
    (c) Microsoft Corporation. All rights reserved.
    X:\sources>notepad
    X:\sources>DISM /image:X:\ /Get-Packages
    Deployment Image Servicing and Management tool
    Version: 10.0.26100.2454
    Error: 87
    The /Image option that is specified points to a running Windows installation.
    To service the running operating system, use the /Online option. For more information, refer to the help by running DISM.exe /Online /?.
    The DISM log file can be found at X:\windows\Logs\DISM\dism.log
    X:\sources>notepad
    X:\sources>

    Ran Startup instructions:
    results Sad Face with Blue Screen "Your device ran into a problem ...." came up, then back to BitLocker recovery enter key

    NOTE: Computer appears to still power off when no action :(

    Sorry! I missed the bios part! Let me send that shortly!!! :(

    Rebooted after restoring defaults, Sad Face Blue Screen "Your device didn't start properly...." th Enter the recovery key to get going again......>Automatic Repair > Your PC did no start correctly Press Restart to restart your PC which can sometimes ....... > restart > Black screen Asus in search of incredible ->Sad Face with Blue Screen "Your device ran into a problem ...." came up, then back to BitLocker recovery enter key
     
    Last edited: Aug 23, 2025
  28. Oh My!

    Oh My! Malware Expert Staff Member

    It is possible this is related to a hardware issue. Since you have not mentioned it, I doubt you have it but check to see if you have MyASUS in WinRE. If you don't have it installed you can create a bootable USB if your computer supports the Cloud Recovery requirement. See Create MyASUS in WinRE For USB. This would be the easiest avenue to test things.

    Booting to your computer Recovery Environment Command Prompt type wmic qfe list then hit Enter. Let me know if you get an error or windows update information.
     
    wolfal likes this.
  29. beckylousiana

    beckylousiana Corporal

    I am sorry I have been MIA! I had a health emergency but I am UP TO SNUFF now! My working computer has quit working... Black Screen and will not turn off.. But we have bought another computer and I hope we don't kill this one.... I will get back onto your instruction asap. THANX!
     
  30. Oh My!

    Oh My! Malware Expert Staff Member

    Very sorry to hear that. Glad you are well enough now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds