Computer Stuck In Weird Loop

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chaos Annihilator, Jul 29, 2026.

  1. Chaos Annihilator

    Chaos Annihilator Specialist

    Sorry it took me a couple hours to get to this. It did not work. There was one restore point, but it was dated 7/31 at 10 a.m. or so, after the major problems if I am remembering correctly.

    It tried, but in the end it says:

    System Restore did not complete successfully. Your computer's system files and settings were not changed.

    Details:
    System Restore failed while scanning the file system on the drive C:\
    The drive might be corrupt. You might want to retry System Restore after running chkdsk /R on this disk.
    An unspecified error occurred during System Restore. (0x80070571)

    You can try System Restore again and choose a different restore point. If you continue to see this error, you can try an advanced recovery method.


    I can only click Close.

    Can we run chkdsk /R from here?
     
  2. Oh My!

    Oh My! Malware Expert Staff Member

    Yes, from the command prompt type chkdsk c: /r and hit Enter
     
  3. Chaos Annihilator

    Chaos Annihilator Specialist

    It is still working on it, maybe we're finally getting somewhere.
     
  4. Oh My!

    Oh My! Malware Expert Staff Member

    We will see what happens. It could be a hardware issue.
     
  5. Chaos Annihilator

    Chaos Annihilator Specialist

    It finished when I wasn't looking. Nothing screamed success, but it seems it was able to complete. I shut down and restarted though, and it is still in the same loop. Pictures of what chkdsk said when it was done are attached.

    We can't fix it if it's a hardware issue, can we?
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    If it is a hard drive issue the resolution would be to replace the drive. We can run a test to check the drive after completing the below.

    Although I don't expect things to change, if you haven't done so already try the System Restore again.
     
  7. Chaos Annihilator

    Chaos Annihilator Specialist

    I'm working on the system restore now. Before her computer totally stopped working, you had a fix list for us. If I open up Hirens, and also put in the USB with FRST to run the fix, would that do any good?
     
  8. Chaos Annihilator

    Chaos Annihilator Specialist

    It did not work, and put up the same message at the end as it did before:

    System Restore did not complete successfully. Your computer's system files and settings were not changed.

    Details:
    System Restore failed while scanning the file system on the drive C:\
    The drive might be corrupt. You might want to retry System Restore after running chkdsk /R on this disk.
    An unspecified error occurred during System Restore. (0x80070571)

    You can try System Restore again and choose a different restore point. If you continue to see this error, you can try an advanced recovery method.

    There is no other restore point to choose. Would an advanced recovery method work without one? I think the only restore point we have is too late.
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    FRST64 will not run through Hirens

    Let's run a test on the hard drive.
    • Double click Utilities
    • Double click Hard Disk Tools
    • Double click Diagnostic
    • Double click WD Data Lifeguard Diagnostics
    • Accept the agreement then click Next
    • Double click on your C: drive (ST1000LM035-1RK172)
    • Click QUICK TEST then click Start
    • Click OK on the warning window
    • After the test completes click Close
    • Report the results
     
  10. Chaos Annihilator

    Chaos Annihilator Specialist

    It took 1 minute, and says Test completed successfully with a green check. I click close, and notice that in the window where I clicked Quick Test, there is now a green check and PASS next to it. Are there more results somewhere besides this?
     
  11. Chaos Annihilator

    Chaos Annihilator Specialist

    I just clicked "View Test Results", and it says it can't reach the page because I'm not connected to the internet or something.
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for going through all of that. It seems the drive is not the issue.

    Please do this.

    • While in Hirens double click on the Accessories folder
    • Double click on the Explorer folder
    • Navigate to the following locations and tell me the file sizes (under Type it will say File)
    C:\Windows\System32\config\software
    C:\Windows\System32\config\system
    C:\FRST\Hives\software
    C:\FRST\Hives\system
    • Report the 4 files sizes in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • File sizes
     
  13. Chaos Annihilator

    Chaos Annihilator Specialist

    Okay,

    C:\Windows\System32\config\software 8,448 KB
    C:\Windows\System32\config\system 21,504 KB
    C:\FRST\Hives\software 118,568 KB
    C:\FRST\Hives\system 21,304 KB

    What are you thinking now, or do you know yet?
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    This enormous file size difference means the software file Windows is using during the boot process is significantly crippled. Via the below I am hoping we are going to stop the repair loop and get some options back.

    As an overview, to make the below more understandable, we want to replace the current files in the system32 folder with the backup files FRST64 created when you ran the initial FRST64 scan.

    Please do this.

    • Rename C:\Windows\System32\config\software to softwareold
    • Rename C:\Windows\System32\config\system to systemold
    • Right click on C:\FRST\Hives\software and select Copy
    • Right click on the C:\Windows\System32\config folder and select Paste
    • Right click on C:\FRST\Hives\system and select Copy
    • Right click on the C:\Windows\System32\config folder and select Paste

    See if you can boot or if you can get into the Recovery Environment with the options we once had.
     
    Chaos Annihilator likes this.
  15. Chaos Annihilator

    Chaos Annihilator Specialist

    Yes! You're amazing! It booted normally, we're back to the original problem! I can see her desktop, it's not in safemode, the right of her taskbar is weirdly empty, there's a strange icon that looks like Logitech whatever it is for her mouse, and a security warning saying her internet security prevented one or more files from being opened.

    It may make it restart, but I can look around in the settings and see if it's still connecting to the internet while saying it can't and all that.
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Finally, some good news.

    Would you be able to run a FRST scan in Normal Boot?
     
  17. Chaos Annihilator

    Chaos Annihilator Specialist

    I was just going to ask you that. Before, when I would go to MajorGeeks and try to download FRST it would restart her computer before I could download it. It does say she's offline when she is really online, like at first. Should I try downloading FRST to her computer and see if I can, or should I just put in the USB I had FRST on and do it from there?
     
  18. Chaos Annihilator

    Chaos Annihilator Specialist

    Nevermind, it did let me download it, but I can't open it. It says the internet security settings prevented it. I'll try it from the USB.
     
  19. Chaos Annihilator

    Chaos Annihilator Specialist

    I'm having trouble getting it to open from the USB, too. It did once, but also with another security warning. I think it would have worked, but I closed the security warning and that automatically closed FRST. I tried to open it again, but it's not working so far. Maybe I need to give it more time, I'll keep trying and let you know if I get the scans done.
     
  20. Oh My!

    Oh My! Malware Expert Staff Member

    We need to be careful with this so pause for a bit and do this.

    On another computer download a new FRST64 file and save it onto a USB.
    On the compromised computer navigate to C:\FRST, right click on it, select Send to, then select Compressed (zipped) folder.
    A zipped folder will be placed on the Desktop. Copy that zipped folder onto the USB
     
  21. Chaos Annihilator

    Chaos Annihilator Specialist

    Sorry, I had to go do something and just came back and saw your last post. FRST started working shortly after my last post, and the scan just finished and says it saved logs on my USB. Should I give you those, or follow the next steps? Or did I already break something?
     
  22. Chaos Annihilator

    Chaos Annihilator Specialist

    Her computer looks okay and is still in normal boot. I will wait for you.
     
  23. Oh My!

    Oh My! Malware Expert Staff Member

    Not sure what you mean by looks OK. Does that mean Normal Boot is working OK?

    We should be OK. Attach both reports to your reply.
     
  24. Chaos Annihilator

    Chaos Annihilator Specialist

    I guess I meant nothing drastically more wrong looking as opposed to before I got FRST to scan. It hasn't restarted itself, like it was continually when I started this thread, but otherwise it is still messed up and I can't get the logitech Windows Security warning to go away, and the right side of her task bar is still blank.

    Logs are attached.
     

    Attached Files:

  25. Oh My!

    Oh My! Malware Expert Staff Member

    Does your copy of FRST.txt look like the below at the top of the report:


    ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
     
  26. Chaos Annihilator

    Chaos Annihilator Specialist

    I had to go look, and yes it does. Why would that be? I guess the scan didn't work after all...?
     
  27. Chaos Annihilator

    Chaos Annihilator Specialist

    The end of the report is the same way, and in the middle of the Addition report there are tons of question marks in squares.
     
  28. Oh My!

    Oh My! Malware Expert Staff Member

    It appears to be a text encoding issue.

    Navigate to the C:\WINDOWS\Minidump folder, zip it in the manner I described in Post #120 and attach it to your reply.
     
  29. Chaos Annihilator

    Chaos Annihilator Specialist

    When I try to zip the Minidump folder, a message pops up that says:

    An unexpected error is keeping you from copying hte file. If you continue to receive this error, you can use the error code to search for help with this problem.

    Error 0x80070005: Access is denied.

    I can click "try again", which does not work, or "Skip". I get this message with each file in the folder, so if I skip them all, we end up with an empty zip folder.
     
  30. Oh My!

    Oh My! Malware Expert Staff Member

    See if you can complete this.

    ===================================================

    Farbar Recovery Scan Tool - Run Fix Using Attached File

    --------------------
    • Download the attached file and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
    • Right click on FRST and select Run as administrator
    • Click Fix and once completed your computer will reboot
    • The tool will create a log on the desktop called Fixlog.txt
    • Copy and paste the contents of the report in your reply.
    • The tool will create a zipped folder on the Desktop with today's date. Attach it to your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Attached zip file
     

    Attached Files:

  31. Chaos Annihilator

    Chaos Annihilator Specialist

    Okay, I'll try it and let you know. I have to step away for a couple of hours, and you'll probably be gone by then. At least we're making headway today! Thanks for your help.

    Should I not shut down the computer when I'm done for tonight? Do we need to be worried about it not coming back on, or being unable to boot into normal mode again? It might be best to leave it like it is, I'm thinking, just in case...?
     
  32. Oh My!

    Oh My! Malware Expert Staff Member

    I think it would be fine but let's leave it on maybe with a document or something on the desktop so if it restarts on its own you will know.

    Tomorrow I would also like you to do this.


    ===================================================

    Process Monitor Boot Log

    --------------------
    • Download Process Monitor and save it to your Desktop
    • Right click on Procmon and select Run as administrator
    • Agree to any permission requests
    • Hit Ctrl + E to stop capturing events
    • Hit Ctrl + X at the same time to clear the display
    • Click Options then Enable Boot Logging
    • Place a check mark in Generate thread profiling events
    • Click OK
    • Close Process Monitor
    • Close any open programs and shut down your computer
    • Start your computer and allow the boot up process to complete, including logging in if you use a password
    • Wait 15 minutes before doing anything further
    • Right click on Process Monitor and select Run as administrator
    • Click Yes on the next window that appears and save the boot-time activity log onto your desktop using the default name
    • Please zip and upload the file to GoFile or the file hosting site of your choice and post the download link in your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Download link
     
  33. Chaos Annihilator

    Chaos Annihilator Specialist

    Pretty smart, Detective, I wouldn't have thought of that.

    I tried to run FRST from the desktop, but it wouldn't open, saying the internet security was blocking it. So I tried from the USB, but nothing would happen: I'd click it, but it would never open. I soon found out my old USB was busted, as the whole thing stopped working completely and would not read no matter which computer or port I put it in (what I get for paying $2 for it on Aliexpress). I am out of USB drives again, so I ordered a couple more. I was stumped for a few hours, but then finally realized the internet security warning that was stopping me from opening things on the desktop was like the one I was getting on my computer when I would try to open internet shortcuts. I remembered how you told me to right click and unblock it, so I tried that with FRST and it finally opened! The fix completed, but FRST said the computer needed to restart.

    When it restarted, it put us back in the Preparing Automatic Repair/ Your computer encountered a problem and needs to restart/Restart/Preparing Automatic Repair loop.

    So I started Hiren's up again, and checked the files you had me check earlier that fixed it, but they are not as different as they were:

    C:\Windows\System32\config\software 106,752 KB
    C:\Windows\System32\config\system 21,304 KB
    C:\FRST\Hives\software 118,568 KB
    C:\FRST\Hives\system 21,304 KB

    I didn't want to mess something up, especially since it seems like the problem may be different now, so I just shut the computer down.

    So, I do not have the Fix log or the zip folder, but they should be on the desktop of my friends computer if we can find the desktop again. I did not get far enough to download Process Monitor.

    When I was having trouble opening internet shortcuts on my computer, you said you thought it was an update issue. I didn't realize until now, but it is the same windows security thing that came up then that is on my friend's computer. I'm thinking the whole corruption isn't because of her mouse, or Logitech Setpoint, but since Logitech Setpoint (or whatever it's called) tries to run when it starts up, something blocks it... Could the same thing be blocking all of the right side of her task bar: the clock, flux, everything?

    I hope this post is literate enough, it's getting late, and her computer should be glad it's not spending the night out on the road...
     
  34. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for the informative reply and for pausing.

    Nothing in the Fixlist should have caused the loop to return.

    Some changes were made to the software file. Please repeat the process of renaming C:\Windows\System32\config\software to C:\Windows\System32\config\softwareold2 then copy/paste C:\FRST\Hives\software to C:\Windows\System32\config. Let me know if it boots.
     
  35. Chaos Annihilator

    Chaos Annihilator Specialist

    It did not boot into normal mode, it is still Preparing Automatic Repair.

    I could tell what you were doing with the fix and knew it wasn't that. I wondered if simply the restart did it (because it was as delicate as I feared) or if I broke something when I ran the FRST scans not realizing you told me to stop?

    Why would changing the file have worked once, but not now?
     
  36. Chaos Annihilator

    Chaos Annihilator Specialist

    My new USB sticks arrived this morning. I may be able to go into Hirens and find the desktop in her C drive and attach the fix log and zip file, if that would help any.
     
  37. Oh My!

    Oh My! Malware Expert Staff Member

    Disappointing. You didn't do anything wrong.

    Give this a try.

    • While in Hirens double click on the Accessories folder
    • Double click on the Explorer folder
    • Navigate to the C:\WINDOWS\Minidump folder and attempt to save it onto a USB device
    • Navigate to the C:\Windows\System32\LogFiles\Srt folder and do the same
    • If successful zip and attach the files to your reply

    • While in Hirens double click Utilities
    • Double click BCD-MBR Tools
    • Double click EasyBCD
    • Click Tools, Options, then select Run EasyBCD in Expert Mode
    • Click OK
    • Click on Useful Utilities
    • Click on the Terminal icon (middle of top row)
    • Type bcdedit /set {default} safeboot minimal then hit Enter
    • If successful shut down Hirens and your computer then attempt to boot the computer
     
  38. Chaos Annihilator

    Chaos Annihilator Specialist

    The first worked, but it says the zipped Minidump file is too large to attach. Should I GoFile it?

    Still working on the second part....
     

    Attached Files:

    • Srt.zip
      File size:
      2.1 MB
      Views:
      2
  39. Oh My!

    Oh My! Malware Expert Staff Member

  40. Chaos Annihilator

    Chaos Annihilator Specialist

    The second part with the bcdedit was successful, yet we are still in the same loop. This was supposed to fix it so we could actually get to the windows recovery environment, right? Would it help to try to force it by shutting it down three times in a row or doing something else like that (that didn't work before)?

    Could the reason replacing the files didn't work this time be because we only did the Software file, and not the System file? I know the size of the System file did not change, but could the contents of it changed anyway?

    Here is the Gofile link: https://gofile.io/d/EcpuFY
     
  41. Chaos Annihilator

    Chaos Annihilator Specialist

    For the bcd edit command; since we ran it through Hiren's, should we have specified the C drive in the command, like we did chkdsk /r?
     
  42. Oh My!

    Oh My! Malware Expert Staff Member

    Since the computer booted at one point the Boot Configuration Data file should be fine. That is unless something corrupted it upon reboot which I doubt.

    The 3 power down step is just a different way of trying to get into the Recovery Environment. It won't help us.

    Go ahead and replace the system and software files again. I did notice the system file was the same size but it doesn't hurt to try what worked before.
     
  43. Chaos Annihilator

    Chaos Annihilator Specialist

  44. Oh My!

    Oh My! Malware Expert Staff Member

    I'll need a bit of time to figure out if we have any other options...
     
    Chaos Annihilator likes this.
  45. Oh My!

    Oh My! Malware Expert Staff Member

    I want to start with this before the power drain.

    ===================================================

    Testing Computer Memory Using MemTest86 USB

    --------------------

    Warning! This step will remove all existing information from your USB device.
    • On a working computer download MemTest86 Free for USB and and save it to your Desktop
    • Unzip the folder onto your Desktop
    • Open the memtest86-usb folder
    • Right click on imageUSB.exe and select Run as administrator
    • Insert your USB into your affected computer then click Refresh Drives
    • Place a check mark in the USB drive now listed under Step 1
    • Confirm the image of the downloaded file is listed as Desktop\memtest86-usb\memtest86-usb.img under Step 3
    • Click Write under Step 4, then click Yes twice to confirm
    • Once completed click OK, then Exit
    • Insert the USB into the compromised computer
    • Boot to the USB device
    • Allow the program to load, start automatically and complete the 4 passes. This process may take some time to complete
    • Report the results of the test
     
  46. Chaos Annihilator

    Chaos Annihilator Specialist

    Wow, you did come up with something else, I thought we might be hitting the end of the road!

    It's been a rough day so far, and my brain is kind of slow. Is a step missing?
    It seems I put this stuff on my desktop to start, and then use the USB in the broken computer. At what point do I put it on the USB?
    Is this a delicate process where I could accidentally wipe my computer instead of the USB?

    When we put this new USB into the broken computer, we boot to it, right? So we don't use Hirens and access both USBs at once?

    Am I able to use/wipe the Hirens or Windows 11 USBs, or do you think we may still need those? (I have others if needed, just wondering).

    Sorry to start out with so many questions, I feel like I'm running on half power today (not enough coffee to fix this one).
     
  47. Oh My!

    Oh My! Malware Expert Staff Member

    I am identifying others as well.

    Since you paused let's try some simpler things.

    Try the 3 times boot interrupt like you mentioned before and see if you get to the Recovery Options.
     
  48. Chaos Annihilator

    Chaos Annihilator Specialist

    Thanks for your determination, your knowledge seems endless.

    I was going to see if you knew a command prompt that could wipe a day from the hard drive of Earth, but now I'm wondering if this day has exhausted the universe's bag of bad luck, because we suddenly may have struck gold...

    I just now got to work on this computer today, so other than giving it dirty looks when I walk by, I haven't done anything. I just saw your last post, and so without much enthusiasm, I turned it off and on three times.

    We're in Safemode!

    It didn't do any sort of repair, and skipped the recovery environment, and just booted into safemode.

    I imagine you're done for today (hopefully you had a good one). I'm going to leave the computer like it is, open a document so we can tell if it restarts in the night, and hope it is still in Safemode tomorrow! I won't give it any more dirty looks, maybe it won't restart itself.
     
  49. Oh My!

    Oh My! Malware Expert Staff Member

    I teleported some threats into the cloud. I guess it found its way home. Hidden talent......

    It went into Safe Mode because of a BCDEdit command we ran while in Hirens.

    My brain is fried and I need to take a break. If you can, leave it as is until tomorrow. I am heading out very early for a bike ride so I won't be back until afternoon, my time. I will have lots of time to think about what we should do next since a miracle has sprung upon us. I don't want a repeat of out last Safe Mode experience.

    Thanks for hanging in there. I have sucked you into my stubbornness.
     
    Chaos Annihilator likes this.
  50. Chaos Annihilator

    Chaos Annihilator Specialist

    That's alright, it has been kind of an amazing ride, actually!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds