TechSpot

Windows find a critic error and will restart in a minute

Solved
By irvingsponch
Jun 20, 2013
  1. Hi, I have a problem starting windows, everything begins when I was using my laptop and I decided to shut down it, but during the proccess the battery energy runs out and the laptop was shut down abruptly, then when I start windows I get the message "windows find a critic error and will restart in a minute" every time.
    So searching for an answer I found reponses to another users, so I follow instructions to the point to run frst, so I have the two txt files
    in the process:

    FRST.txt:

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2013
    Ran by SYSTEM on 20-06-2013 21:07:16
    Running from F:\
    Windows 7 Ultimate (X64) OS Language: Spanish Modern Sort
    Internet Explorer Version 9
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe [618368 2009-07-04] (ELAN Microelectronic Corp.)
    HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7970848 2009-07-14] (Realtek Semiconductor)
    HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
    HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice [2716216 2009-11-16] (ESET)
    Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
    HKLM-x32\...\Run: [BTMeter] C:\Program Files (x86)\Battery Meter\BTMeter.exe [623984 2009-07-02] (Dell)
    HKLM-x32\...\Run: [WSED] C:\Program Files (x86)\WSED\WSED.exe [247080 2009-05-27] (Dell)
    HKLM-x32\...\Run: [] [x]
    HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [x]
    HKLM-x32\...\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [198160 2009-12-27] (RealNetworks, Inc.)
    HKLM-x32\...\Run: [nusbantivirus] "C:\Program Files (x86)\Naevius USB Antivirus\usbantivirus.exe" -hide [x]
    HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-12] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKU\Irving Omar\...\Run: [Facebook Update] "C:\Users\Irving Omar\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-12-13] (Facebook Inc.)
    Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
    ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

    ==================== Services (Whitelisted) =================

    S3 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-15] (Adobe Systems Incorporated)
    S2 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [79360 2011-11-04] (Autodesk)
    S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [23296 2009-11-16] (ESET)
    S2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [735960 2009-11-16] (ESET)
    S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-10-18] ()
    S2 mi-raysat_3dsMax2009_32; C:\Program Files (x86)\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [65536 2008-03-10] ()
    S2 mi-raysat_3dsMax2009_64; C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_64server.exe [65536 2008-03-10] ()
    S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29178224 2007-02-10] (Microsoft Corporation)
    S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)
    S4 OracleJobSchedulerTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
    S4 OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe [102400 2006-02-02] ()
    S3 OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe [57616 2006-02-02] (Oracle Corporation)
    S3 OracleServiceTecSal; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
    S2 OracleServiceXE; c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE [59064320 2006-02-02] (Oracle Corporation)
    S3 OracleXEClrAgent; C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe [45056 2006-02-02] ()
    S2 OracleXETNSListener; C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [204800 2006-02-02] ()
    S2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [13234176 2012-11-01] ()
    S3 wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [21504 2010-10-24] (Apache Software Foundation)
    S3 wampmysqld; c:\wamp\bin\mysql\mysql5.1.53\bin\mysqld.exe [7669760 2010-11-24] ()
    S2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [33280 2009-07-17] ()
    S2 matlabserver; C:\MATLAB7\webserver\bin\win32\matlabserver.exe [x]

    ==================== Drivers (Whitelisted) ====================

    S2 eamon; C:\Windows\System32\DRIVERS\eamon.sys [145336 2009-11-16] (ESET)
    S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [136584 2009-11-16] (ESET)
    S2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169080 2009-11-16] (ESET)
    S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2009-06-19] (ESET)
    S2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [44944 2009-11-16] (ESET)
    S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
    S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
    S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
    S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
    S3 MSIRCOMM; C:\Windows\System32\DRIVERS\MSIRCOMM.sys [30208 2009-07-14] (Microsoft Corporation)
    S0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-07-05] (Duplex Secure Ltd.)
    S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
    S1 vmm; C:\Windows\system32\Controladores\vmm.sys [296816 2007-02-18] (Microsoft Corporation)
    S0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc.)
    S1 SASDIFSV; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x]
    S1 SASKUTIL; \??\C:\Users\IRVING~1\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x]

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
    2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
    2013-06-20 02:09 - 2013-06-20 23:53 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
    2013-06-20 01:52 - 2013-05-08 17:45 - 2254110720 ____A C:\Users\Irving Omar\Desktop\sol-10-u11-ga-x86-dvd.iso
    2013-06-19 22:39 - 2013-06-20 23:44 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
    2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
    2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
    2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
    2013-06-18 02:53 - 2013-06-18 02:54 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
    2013-06-17 18:57 - 2013-06-17 18:58 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
    2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
    2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
    2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
    2013-06-17 15:20 - 2013-06-17 15:22 - 00000000 ____D C:\Program Files (x86)\Eclipse
    2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
    2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
    2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
    2013-06-16 22:50 - 2013-06-16 23:00 - 00000000 ____D C:\cygwin
    2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
    2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
    2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files\iTunes
    2013-06-09 21:33 - 2013-06-09 21:34 - 00000000 ____D C:\Program Files (x86)\iTunes
    2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
    2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
    2013-05-31 05:44 - 2013-06-10 20:41 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
    2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2013-05-25 01:29 - 2013-06-08 23:08 - 00000000 ____D C:\Program Files\My Dell

    ==================== One Month Modified Files and Folders =======

    2013-06-21 02:57 - 2013-05-08 01:59 - 00000000 ____D C:\ProgramData\VMware
    2013-06-21 02:57 - 2012-11-08 02:22 - 00000212 ____A C:\Windows\Tasks\AutoKMS.job
    2013-06-21 02:56 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2013-06-21 02:56 - 2009-07-14 05:51 - 00176657 ____A C:\Windows\setupact.log
    2013-06-21 02:53 - 2010-08-02 21:36 - 00001042 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2013-06-21 02:42 - 2009-07-14 06:10 - 01758736 ____A C:\Windows\WindowsUpdate.log
    2013-06-21 01:44 - 2012-07-12 01:36 - 00000838 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2013-06-21 01:43 - 2009-07-14 06:08 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2013-06-21 01:25 - 2013-06-21 01:25 - 00003288 ____N C:\bootsqm.dat
    2013-06-21 00:01 - 2013-01-13 04:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Skype
    2013-06-21 00:00 - 2010-08-02 21:36 - 00001046 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2013-06-20 23:53 - 2013-06-20 02:09 - 00000000 ____D C:\Users\Irving Omar\Desktop\Solaris 10
    2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\VMware
    2013-06-20 23:53 - 2013-05-08 02:05 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\VMware
    2013-06-20 23:44 - 2013-06-19 22:39 - 00000000 ____D C:\Users\Irving Omar\Documents\MobaXterm
    2013-06-20 23:42 - 2010-04-28 22:54 - 00000000 ___RD C:\Users\Irving Omar\Descargas de Google Chrome
    2013-06-20 22:15 - 2012-12-13 05:10 - 00000952 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000UA.job
    2013-06-20 21:06 - 2013-06-20 21:06 - 00000000 ____D C:\FRST
    2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-06-20 18:10 - 2009-07-14 05:45 - 00031120 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-06-20 04:15 - 2012-12-13 05:10 - 00000930 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2898004258-2142751285-386409930-1000Core.job
    2013-06-20 01:54 - 2009-07-14 10:31 - 00745454 ____A C:\Windows\System32\perfh00A.dat
    2013-06-20 01:54 - 2009-07-14 10:31 - 00154016 ____A C:\Windows\System32\perfc00A.dat
    2013-06-20 01:54 - 2009-07-14 06:13 - 01669842 ____A C:\Windows\System32\PerfStringBackup.INI
    2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ___RD C:\Program Files (x86)\Skype
    2013-06-19 04:05 - 2013-01-13 04:49 - 00000000 ____D C:\ProgramData\Skype
    2013-06-18 16:07 - 2013-06-18 16:07 - 00002122 ____A C:\Users\Public\Desktop\Belarc Advisor.lnk
    2013-06-18 16:07 - 2013-06-18 16:07 - 00000000 ____D C:\Program Files (x86)\Belarc
    2013-06-18 02:54 - 2013-06-18 02:54 - 00001774 ____A C:\Users\Irving Omar\Documents\Solicitud de inscripción.htm
    2013-06-18 02:54 - 2013-06-18 02:53 - 00000000 ____D C:\Users\Irving Omar\Documents\Solicitud de inscripción_archivos
    2013-06-17 19:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\System32\NDF
    2013-06-17 18:58 - 2013-06-17 18:57 - 00000000 ____D C:\Users\Irving Omar\Documents\TXM
    2013-06-17 17:29 - 2013-06-17 17:29 - 00001179 ____A C:\Users\Irving Omar\Desktop\Google Talk.lnk
    2013-06-17 17:29 - 2010-08-02 21:36 - 00000000 ____D C:\Program Files (x86)\Google
    2013-06-17 17:29 - 2010-02-10 23:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Google
    2013-06-17 15:47 - 2009-07-14 05:45 - 03380464 ____A C:\Windows\System32\FNTCACHE.DAT
    2013-06-17 15:31 - 2013-06-17 15:31 - 00000000 ____D C:\Users\Irving Omar\ssh
    2013-06-17 15:31 - 2009-12-25 20:33 - 00000000 ____D C:\users\Irving Omar
    2013-06-17 15:28 - 2011-05-06 00:26 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\Eclipse
    2013-06-17 15:28 - 2009-12-25 20:33 - 00143456 ____A C:\Users\Irving Omar\AppData\Local\GDIPFONTCACHEV1.DAT
    2013-06-17 15:23 - 2013-06-17 15:23 - 00000000 ____D C:\Users\Irving Omar\.eclipse
    2013-06-17 15:22 - 2013-06-17 15:20 - 00000000 ____D C:\Program Files (x86)\Eclipse
    2013-06-17 15:18 - 2013-06-17 15:18 - 00001164 ____A C:\Users\Public\Desktop\TeamViewer 8.lnk
    2013-06-17 15:18 - 2013-06-17 15:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2013-06-16 23:00 - 2013-06-16 23:00 - 00000579 ____A C:\Users\Public\Desktop\Cygwin Terminal.lnk
    2013-06-16 23:00 - 2013-06-16 22:50 - 00000000 ____D C:\cygwin
    2013-06-16 22:58 - 2013-06-16 22:58 - 00001061 ____A C:\Users\Irving Omar\Desktop\Notepad++.lnk
    2013-06-16 22:58 - 2013-03-24 19:15 - 00000000 ____D C:\Users\Irving Omar\AppData\Roaming\Notepad++
    2013-06-16 22:58 - 2013-03-24 19:13 - 00000000 ____D C:\Program Files (x86)\Notepad++
    2013-06-16 01:53 - 2009-12-27 23:37 - 00000000 ____D C:\Users\Irving Omar\Desktop\Juegos
    2013-06-14 01:24 - 2013-06-14 01:24 - 00000000 ____D C:\Program Files\7-Zip
    2013-06-12 02:49 - 2012-04-04 18:22 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2013-06-12 02:49 - 2011-05-18 23:01 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2013-06-10 20:41 - 2013-05-31 05:44 - 00000000 ____D C:\Users\Irving Omar\Documents\Resumes
    2013-06-09 21:34 - 2013-06-09 21:34 - 00001785 ____A C:\Users\Public\Desktop\iTunes.lnk
    2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iTunes
    2013-06-09 21:34 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files (x86)\iTunes
    2013-06-09 21:33 - 2013-06-09 21:33 - 00000000 ____D C:\Program Files\iPod
    2013-06-08 23:08 - 2013-05-25 01:29 - 00000000 ____D C:\Program Files\My Dell
    2013-06-07 04:02 - 2011-07-14 17:24 - 00000000 ____D C:\wamp
    2013-06-03 02:49 - 2013-06-03 02:49 - 00000000 ____D C:\Users\Irving Omar\AppData\Local\{34D7EF03-F30A-4C7A-8FFE-3F455F43D503}
    2013-06-03 02:48 - 2009-12-25 21:52 - 00000000 ____D C:\Users\Irving Omar\Tracing
    2013-06-03 01:06 - 2009-12-29 22:10 - 00000000 ___HD C:\Users\Irving Omar\Documents\videos obtenidos
    2013-05-28 02:21 - 2012-05-09 02:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2013-05-26 20:49 - 2013-05-26 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2013-05-25 01:30 - 2011-05-24 23:46 - 00000000 ____D C:\Program Files\Dell Support Center
    2013-05-25 01:29 - 2009-11-04 20:19 - 00000000 ____D C:\ProgramData\PCDr

    ==================== Known DLLs (Whitelisted) ================


    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 28%
    Total physical RAM: 1976.89 MB
    Available physical RAM: 1405.65 MB
    Total Pagefile: 1976.89 MB
    Available Pagefile: 1401.44 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.86 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:281.47 GB) (Free:166.5 GB) NTFS (Disk=0 Partition=3)
    Drive f: () (Removable) (Total:1.88 GB) (Free:1.88 GB) FAT (Disk=2 Partition=1)
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:10.39 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D6385E59)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=281 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=2 GB) - (Type=OF Extended)

    ========================================================
    Disk: 2 (Size: 2 GB) (Disk ID: 00000000)
    Partition 1: (Active) - (Size=2 GB) - (Type=06)


    LastRegBack: 2013-06-14 02:09

    ==================== End Of Log ============================

    and the Services.txt:


    Farbar Recovery Scan Tool (x64) Version: 21-06-2013
    Ran by SYSTEM at 2013-06-20 21:18:45
    Running from F:\
    Boot Mode: Recovery

    ================== Search: "services.exe" ===================

    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    C:\Windows\System32\services.exe
    [2009-07-14 00:19] - [2009-07-14 02:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

    ====== End Of Search ======

    I hope you can help and thanks for your attention
  2. Broni

    Broni Malware Annihilator Posts: 46,447   +252

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =======================================

    I actually don't see anything malicious there but let's see if we can make your computer bootable again.

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
    See if you can boot normally.

    Attached Files:

  3. irvingsponch

    irvingsponch Newcomer, in training Topic Starter

    Here is the fixlog.txt:

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-06-2013
    Ran by SYSTEM at 2013-06-20 22:43:22 Run:1
    Running from F:\
    Boot Mode: Recovery
    ==============================================

    DEFAULT hive was successfully copied to System32\config\HiveBackup
    DEFAULT hive was successfully restored from registry back up.
    SAM hive was successfully copied to System32\config\HiveBackup
    SAM hive was successfully restored from registry back up.
    SECURITY hive was successfully copied to System32\config\HiveBackup
    SECURITY hive was successfully restored from registry back up.
    SOFTWARE hive was successfully copied to System32\config\HiveBackup
    SOFTWARE hive was successfully restored from registry back up.
    SYSTEM hive was successfully copied to System32\config\HiveBackup
    SYSTEM hive was successfully restored from registry back up.

    ==== End of Fixlog ====

    the boot is in progress
  4. irvingsponch

    irvingsponch Newcomer, in training Topic Starter

    It seems it worked!! thank you so much, really, thanks, and thanks for being so patient, as you can see I'm totally a newbie, and when I did not find a solution to this I went crazy, and aslo english is not my native languaje sorry for the bad writting, so thanks for everything
  5. irvingsponch

    irvingsponch Newcomer, in training Topic Starter

  6. Broni

    Broni Malware Annihilator Posts: 46,447   +252

    I'm glad to hear good news :)


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.