Unable To Boot Windows 10 Pc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Thwack, Aug 13, 2017.

  1. Thwack

    Thwack Private E-2

    Hi All
    A friend has just dropped off a PC for me to look at, but I'm stuck.
    The windows 10 system starts then gives a blue screen with the following message
    "Your pc ran into a problem and needs to restart"
    The error is "critical process died"
    It loops between this and diagnosing problem, rebooting each time.
    Apparently the PC failed to sync emails just before it was rebooted, which leads me to think either a virus or failed update.(Are they the same?)

    I have tried starting in safe mode - no difference, so tried "debugging mode" and it created the following file in D:\windows\system32\logfiles\Srt\SrtTrail.txt

    I've pulled the drive from the machine and popped into to a USB dock on a spare PC to access the log files
    It looks like there are 6 dodgy files (in red here, below)
    I've tried looking at the security info, but the security tab is blank.
    I've tried running cacls.exe but that tells me it cannot find the file (that IS listed with a dir command!)
    I've even booted up on Ubuntu to rename or move the files but that tells me it is "unable to perfom the task".
    Windows will not rename nor move the files - with an "access denied" or "cannot find files"
    How should I attack this?

    AVG ran on the drive and found nothing untoward.
    Any help greatly received

    Log files attached
    Hitman Pro found a few items that it feels is malware, but I have installed.
    Ahk2Exe, Service_KMS are used on this machine.
    I installed Tor browser, and asumed the obfs4proxy is part of the process
    Unlocker1.9.2 was an attempt to delete the locked files.. (it failed, so can be removed - as can Tor browser)

    I do have a concern that the scans all seem to be onthe "C:" drive the current OS registry and not on the additional drive (i:) with the issue, I accept you chaps will need a "clean slate" from which to work so I wait your instuction

    Thank you so much for your help.

    Startup Repair diagnosis and repair log
    ---------------------------
    Last successful boot time: ‎8/‎10/‎2017 8:56:50 AM (GMT)
    Number of repair attempts: 12

    Session details
    ---------------------------
    System Disk = \Device\Harddisk0
    Windows directory = D:\WINDOWS
    AutoChk Run = 0
    Number of root causes = 6

    Test Performed:
    ---------------------------
    Name: Check for updates
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: System disk test
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Disk failure diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 79 ms

    Test Performed:
    ---------------------------
    Name: Disk metadata test
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Target OS test
    Result: Completed successfully. Error code = 0x0
    Time taken = 31 ms

    Test Performed:
    ---------------------------
    Name: Volume content check
    Result: Completed successfully. Error code = 0x0
    Time taken = 15 ms

    Test Performed:
    ---------------------------
    Name: Boot manager diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 157 ms

    Test Performed:
    ---------------------------
    Name: System boot log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Event log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 15 ms

    Test Performed:
    ---------------------------
    Name: Internal state check
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Check for pending package install
    Result: Completed successfully. Error code = 0x0
    Time taken = 8344 ms

    Test Performed:
    ---------------------------
    Name: Boot status test
    Result: Completed successfully. Error code = 0x0
    Time taken = 47 ms

    Test Performed:
    ---------------------------
    Name: Setup state check
    Result: Completed successfully. Error code = 0x0
    Time taken = 266 ms

    Test Performed:
    ---------------------------
    Name: Registry hives test
    Result: Completed successfully. Error code = 0x0
    Time taken = 2546 ms

    Test Performed:
    ---------------------------
    Name: Windows boot log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Bugcheck analysis
    Result: Completed successfully. Error code = 0x0
    Time taken = 610 ms

    Test Performed:
    ---------------------------
    Name: Access control test
    Result: Completed successfully. Error code = 0x0
    Time taken = 11890 ms

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\dpapisrv.dll are not proper. Old value = 0x0

    Repair action: Access control repair
    Result: Failed. Error code = 0x2
    Time taken = 0 ms

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\ExSMime.dll are not proper. Old value = 0x0

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\MusNotificationUx.exe are not proper. Old value = 0x0

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\OnDemandConnRouteHelper.dll are not proper. Old value = 0x0

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\usermgrcli.dll are not proper. Old value = 0x0

    Root cause found:
    ---------------------------
    ACLs on file D:\WINDOWS\system32\winsrvext.dll are not proper. Old value = 0x0

    ---------------------------
    ---------------------------
    Session details
    ---------------------------
    System Disk = \Device\Harddisk0
    Windows directory = D:\WINDOWS
    AutoChk Run = 0
    Number of root causes = 1

    Test Performed:
    ---------------------------
    Name: Check for updates
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: System disk test
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Disk failure diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 62 ms

    Test Performed:
    ---------------------------
    Name: Disk metadata test
    Result: Completed successfully. Error code = 0x0
    Time taken = 16 ms

    Test Performed:
    ---------------------------
    Name: Target OS test
    Result: Completed successfully. Error code = 0x0
    Time taken = 47 ms

    Test Performed:
    ---------------------------
    Name: Volume content check
    Result: Completed successfully. Error code = 0x0
    Time taken = 41593 ms

    Test Performed:
    ---------------------------
    Name: Boot manager diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: System boot log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Event log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 3032 ms

    Test Performed:
    ---------------------------
    Name: Internal state check
    Result: Completed successfully. Error code = 0x0
    Time taken = 62 ms

    Root cause found:
    ---------------------------
    Startup Repair has tried several times but still cannot determine the cause of the problem.

    ---------------------------
    ---------------------------
    Session details
    ---------------------------
    System Disk = \Device\Harddisk0
    Windows directory = D:\WINDOWS
    AutoChk Run = 0
    Number of root causes = 1

    Test Performed:
    ---------------------------
    Name: Check for updates
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: System disk test
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Disk failure diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 47 ms

    Test Performed:
    ---------------------------
    Name: Disk metadata test
    Result: Completed successfully. Error code = 0x0
    Time taken = 31 ms

    Test Performed:
    ---------------------------
    Name: Target OS test
    Result: Completed successfully. Error code = 0x0
    Time taken = 47 ms

    Test Performed:
    ---------------------------
    Name: Volume content check
    Result: Completed successfully. Error code = 0x0
    Time taken = 41828 ms

    Test Performed:
    ---------------------------
    Name: Boot manager diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: System boot log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 0 ms

    Test Performed:
    ---------------------------
    Name: Event log diagnosis
    Result: Completed successfully. Error code = 0x0
    Time taken = 3625 ms

    Test Performed:
    ---------------------------
    Name: Internal state check
    Result: Completed successfully. Error code = 0x0
    Time taken = 78 ms

    Root cause found:
    ---------------------------
    Startup Repair has tried several times but still cannot determine the cause of the problem.

    ---------------------------
    ---------------------------
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and remove everything it found. Do the same with Hitman.

    Reboot and rescan with both and attach new logs.
     
  3. Thwack

    Thwack Private E-2

    Thank you TimW for your amazingly quick reply.
    You help is so very welcome.

    I have rerun the two apps and had them remove everything, rebooted and rescanned.
    Logs attached as requested

    Many thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. Thwack

    Thwack Private E-2

    Thanks TimW
    You are nothing short of BRILLIANT!!!!!!!
    I really appreciate your assistance
    ATB
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.
     
  7. Thwack

    Thwack Private E-2

    I've had a message asking me to confirm how the PC is.
    It is free of malware but still not booting and I'm still unable to rename, delete or even change the ACL on 6 files in the windows\system32 directory that the diags is claiming are causing a "critical process died" As a result the system does not boot and isstuck in a loop as described in my initial post.
    I reposted the thread as I (incorrectly) assumed this was the incorrect forum, now the system is malware clear.
    Sorry.
    Any assisance greatly received.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I understand, however, this is a subject for the software forum. Please post a new thread there.
     
  9. Thwack

    Thwack Private E-2

    Thanks TimW.
    I had, and they deleted it telling me it was a duplicate to this and that I must update this thread (as above).
    I guessed it would then be moved to Software.

    Not to worry. Thanks to you and your kind help I have now resolved the issue.
    This thread can be closed.
    I really apprecite all your assistance. Keep up the good work!
    With kind regards
    Thwack
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What was the resolution?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds