Jump to content

FBI virus; can't boot in safe mode


Recommended Posts

I currently have the FBI virus on my laptop.  I generated a FRST.txt file and this is it's contents.  Help would greatly be appreciated!

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-07-2013 03
Ran by SYSTEM on 16-07-2013 20:51:06
Running from G:\
WIN_7 Service Pack 1 (X64) OS Language: English(US)
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Winlogon: [userinit] 
HKLM-x32\...\Winlogon: [userinit]  [x]
HKLM\...\Winlogon: [shell]  [x ] () <=== ATTENTION
HKLM-x32\...\Winlogon: [shell]  [x ] () <=== ATTENTION
HKU\Ryan\...\Run: [Elbserver] - C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay [83344 2011-05-18] (Sony Corporation)
HKU\Ryan\...\Run: [sony Creative Software] - RegSVR32.exe "C:\Users\Ryan\AppData\Local\Sony Creative Software\iitzstbm.dll" [872448 2013-06-28] (CyberLink Corp.) <===== ATTENTION
HKU\Ryan\...\Run: [OutTask32] - rundll32.exe "C:\Users\Ryan\AppData\Roaming\OutTask32\OutTask32.dll",IsCryptCdrom Eventfactory [29184 2013-06-29] () <===== ATTENTION
HKU\Ryan\...\Winlogon: [shell] explorer.exe,C:\Users\Ryan\AppData\Roaming\cache.dat [88576 2011-11-16] () <==== ATTENTION 
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
 
==================== Services (Whitelisted) =================
 
S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 BOINC; C:\Program Files (x86)\BOINC\boinc.exe [537344 2010-09-23] (World Community Grid)
S2 ccEvtMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2010-08-24] (Symantec Corporation)
S2 ccSetMgr; C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe [108392 2010-08-24] (Symantec Corporation)
S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [427432 2013-02-22] ()
S3 LiveUpdate; C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE [3093880 2010-02-17] (Symantec Corporation)
S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-05] ()
S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [258048 2013-03-04] (Sony Corporation)
S2 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe [3234848 2010-08-24] (Symantec Corporation)
S4 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE [425800 2010-08-24] (Symantec Corporation)
S2 Symantec AntiVirus; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [1832072 2010-08-24] (Symantec Corporation)
S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [427432 2013-02-22] ()
S2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [82544 2011-07-12] (Symantec Corporation)
S2 Oasis2Service; "C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe" [x]
 
==================== Drivers (Whitelisted) ====================
 
S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
S3 NAVENG; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130715.021\ENG64.SYS [126040 2013-06-17] (Symantec Corporation)
S3 NAVENG; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130715.021\ENG64.SYS [126040 2013-06-17] (Symantec Corporation)
S3 NAVEX15; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130715.021\EX64.SYS [2098776 2013-06-17] (Symantec Corporation)
S3 NAVEX15; C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20130715.021\EX64.SYS [2098776 2013-06-17] (Symantec Corporation)
S2 risdsnpe; C:\Windows\System32\DRIVERS\risdsnxc64.sys [98816 2011-06-23] (REDC)
S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2012-11-06] ()
S1 SRTSP; C:\Windows\System32\Drivers\SRTSP64.SYS [447536 2010-08-24] (Symantec Corporation)
S1 SRTSP; C:\Windows\SysWow64\Drivers\SRTSP64.SYS [447536 2010-08-24] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL64.SYS [482352 2010-08-24] (Symantec Corporation)
S3 SRTSPL; C:\Windows\SysWow64\Drivers\SRTSPL64.SYS [482352 2010-08-24] (Symantec Corporation)
S1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX64.SYS [32304 2010-08-24] (Symantec Corporation)
S1 SRTSPX; C:\Windows\SysWow64\Drivers\SRTSPX64.SYS [32304 2010-08-24] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [173616 2012-10-31] (Symantec Corporation)
S3 Teefer2; C:\Windows\System32\DRIVERS\teefer2.sys [64048 2010-08-24] (Symantec Corporation)
S1 WPS; C:\Windows\system32\drivers\wpsdrvnt.sys [52784 2010-08-24] (Symantec Corporation)
S3 WpsHelper; C:\Windows\system32\drivers\WpsHelper.sys [233120 2012-10-04] (Symantec Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-07-16 20:51 - 2013-07-16 20:51 - 00000000 ____D C:\FRST
2013-07-15 18:48 - 2013-07-15 18:57 - 00000004 _____ C:\Users\Ryan\AppData\Roaming\cache.ini
2013-07-03 20:07 - 2013-07-03 20:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-03 04:52 - 2013-07-03 04:52 - 00000000 ____D C:\Users\Ryan\AppData\Local\VirtualStore
2013-07-03 04:52 - 2013-07-03 04:52 - 00000000 ____D C:\Users\Ryan\AppData\Local\Evernote
2013-07-03 04:48 - 2013-07-03 04:48 - 00000112 ___RH C:\Users\Ryan\Downloads\Stinger.opt
2013-07-02 12:37 - 2013-07-03 04:48 - 00000000 ____D C:\Program Files (x86)\stinger
2013-07-02 12:37 - 2013-07-02 19:13 - 00000642 _____ C:\Users\Ryan\Downloads\Stinger_02072013_163736.html
2013-07-02 12:37 - 2013-07-02 12:37 - 00490268 _____ C:\Users\Ryan\Downloads\runtime.dat
2013-07-02 12:37 - 2013-07-02 12:37 - 00000000 ____D C:\Stinger_Quarantine
2013-07-02 12:36 - 2013-07-02 12:37 - 11351584 _____ (McAfee Inc) C:\Users\Ryan\Downloads\stinger32.exe
2013-06-29 14:25 - 2013-06-29 14:25 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\OutTask32
2013-06-28 14:23 - 2013-06-30 07:36 - 00000000 ____D C:\Users\Ryan\AppData\Local\Sony Creative Software
2013-06-26 14:44 - 2013-06-26 14:44 - 00003130 _____ C:\Windows\System32\Tasks\USER_ESRV_SVC
2013-06-16 13:43 - 2013-07-02 12:31 - 00000000 ____D C:\Users\Ryan\AppData\Local\Spotify
2013-06-16 13:43 - 2013-06-16 13:43 - 00001762 _____ C:\Users\Ryan\Desktop\Spotify.lnk
2013-06-16 13:40 - 2013-07-02 12:36 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\Spotify
2013-06-16 13:39 - 2013-06-16 13:39 - 00092776 _____ (Spotify Ltd) C:\Users\Ryan\Downloads\SpotifySetup.exe
 
==================== One Month Modified Files and Folders =======
 
2013-07-16 20:51 - 2013-07-16 20:51 - 00000000 ____D C:\FRST
2013-07-15 18:57 - 2013-07-15 18:48 - 00000004 _____ C:\Users\Ryan\AppData\Roaming\cache.ini
2013-07-15 18:57 - 2011-11-02 14:10 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\Dropbox
2013-07-15 18:56 - 2013-01-12 14:18 - 00000396 ____H C:\Windows\Tasks\{4F5ECFC8-7B9B-47B6-9394-AC6A67E3BF01}.job
2013-07-15 18:54 - 2011-11-03 19:49 - 00000000 ____D C:\users\boinc_master
2013-07-15 18:54 - 2011-11-02 10:36 - 00000000 ____D C:\ProgramData\BOINC
2013-07-15 18:54 - 2011-10-27 02:01 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-15 18:54 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-15 18:54 - 2009-07-13 20:45 - 00481912 _____ C:\Windows\System32\FNTCACHE.DAT
2013-07-15 18:53 - 2009-07-13 20:51 - 00137307 _____ C:\Windows\setupact.log
2013-07-15 18:52 - 2011-05-27 13:57 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-15 18:18 - 2012-10-11 18:42 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-15 18:01 - 2011-10-27 01:48 - 01414482 _____ C:\Windows\WindowsUpdate.log
2013-07-15 12:23 - 2011-11-24 18:08 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\Azureus
2013-07-15 11:49 - 2011-11-03 12:58 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-15 11:45 - 2009-07-13 21:13 - 00794094 _____ C:\Windows\System32\PerfStringBackup.INI
2013-07-15 11:24 - 2012-02-11 18:56 - 78185248 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-07-15 11:15 - 2013-05-30 14:48 - 00003340 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1915460752-2971927591-2130414024-1000
2013-07-15 11:15 - 2013-04-20 08:30 - 00003204 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1915460752-2971927591-2130414024-1000
2013-07-15 11:12 - 2009-07-13 20:45 - 00021200 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-15 11:12 - 2009-07-13 20:45 - 00021200 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-11 23:02 - 2012-05-11 23:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 23:02 - 2012-05-11 23:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 18:54 - 2011-11-02 14:11 - 00000000 ___RD C:\Users\Ryan\Dropbox
2013-07-10 23:59 - 2011-05-27 13:57 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-07-10 23:59 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-10 23:59 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-10 23:59 - 2009-07-13 19:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-07-10 23:58 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-07-10 23:56 - 2013-03-21 14:43 - 00000000 ____D C:\ProgramData\Real
2013-07-10 20:16 - 2011-02-10 15:03 - 00773940 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-07-10 20:00 - 2011-11-02 10:33 - 00000000 ____D C:\users\Ryan
2013-07-10 19:40 - 2011-11-08 14:12 - 00000000 ____D C:\Users\Ryan\AppData\Local\CrashDumps
2013-07-07 15:55 - 2012-05-09 18:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-04 12:44 - 2012-10-11 18:42 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-04 12:44 - 2012-10-11 18:42 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-04 12:44 - 2011-11-03 13:11 - 00000000 ____D C:\Users\Ryan\AppData\Local\Adobe
2013-07-04 12:44 - 2011-10-27 02:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-07-03 20:07 - 2013-07-03 20:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-03 04:52 - 2013-07-03 04:52 - 00000000 ____D C:\Users\Ryan\AppData\Local\VirtualStore
2013-07-03 04:52 - 2013-07-03 04:52 - 00000000 ____D C:\Users\Ryan\AppData\Local\Evernote
2013-07-03 04:48 - 2013-07-03 04:48 - 00000112 ___RH C:\Users\Ryan\Downloads\Stinger.opt
2013-07-03 04:48 - 2013-07-02 12:37 - 00000000 ____D C:\Program Files (x86)\stinger
2013-07-02 19:13 - 2013-07-02 12:37 - 00000642 _____ C:\Users\Ryan\Downloads\Stinger_02072013_163736.html
2013-07-02 17:50 - 2013-06-11 14:29 - 00007654 _____ C:\Users\Ryan\AppData\Local\Resmon.ResmonCfg
2013-07-02 12:37 - 2013-07-02 12:37 - 00490268 _____ C:\Users\Ryan\Downloads\runtime.dat
2013-07-02 12:37 - 2013-07-02 12:37 - 00000000 ____D C:\Stinger_Quarantine
2013-07-02 12:37 - 2013-07-02 12:36 - 11351584 _____ (McAfee Inc) C:\Users\Ryan\Downloads\stinger32.exe
2013-07-02 12:36 - 2013-06-16 13:40 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\Spotify
2013-07-02 12:31 - 2013-06-16 13:43 - 00000000 ____D C:\Users\Ryan\AppData\Local\Spotify
2013-07-01 20:38 - 2012-01-17 20:43 - 00000000 ____D C:\Users\Ryan\Desktop\MedSchool
2013-06-30 08:40 - 2011-11-03 19:56 - 00000023 _____ C:\test.xml
2013-06-30 07:36 - 2013-06-28 14:23 - 00000000 ____D C:\Users\Ryan\AppData\Local\Sony Creative Software
2013-06-29 14:25 - 2013-06-29 14:25 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\OutTask32
2013-06-26 14:44 - 2013-06-26 14:44 - 00003130 _____ C:\Windows\System32\Tasks\USER_ESRV_SVC
2013-06-26 14:44 - 2011-11-02 10:45 - 00000021 _____ C:\Windows\Model.txt
2013-06-26 14:44 - 2011-11-02 10:45 - 00000000 _____ C:\Windows\Model.log
2013-06-23 14:17 - 2013-03-21 14:44 - 00000000 ____D C:\Users\Ryan\AppData\Roaming\Real
2013-06-16 13:43 - 2013-06-16 13:43 - 00001762 _____ C:\Users\Ryan\Desktop\Spotify.lnk
2013-06-16 13:39 - 2013-06-16 13:39 - 00092776 _____ (Spotify Ltd) C:\Users\Ryan\Downloads\SpotifySetup.exe
 
Files to move or delete:
====================
C:\Users\Ryan\AppData\Roaming\cache.dat
C:\Users\Ryan\AppData\Roaming\cache.ini
C:\ProgramData\gifnocsm.pad
C:\Windows\Tasks\{4F5ECFC8-7B9B-47B6-9394-AC6A67E3BF01}.job
 
==================== Known DLLs (Whitelisted) ================
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
==================== EXE ASSOCIATION =====================
 
HKLM\...\.exe:  <===== ATTENTION!
HKLM\...\exefile\DefaultIcon:  <===== ATTENTION!
HKLM\...\exefile\open\command:  <===== ATTENTION!
 
==================== Restore Points  =========================
 
Restore point made on: 2013-06-25 13:58:19
Restore point made on: 2013-07-02 20:21:17
Restore point made on: 2013-07-09 23:01:07
Restore point made on: 2013-07-10 20:10:25
Restore point made on: 2013-07-11 18:52:52
Restore point made on: 2013-07-11 23:01:25
 
==================== Memory info =========================== 
 
Percentage of memory in use: 12%
Total physical RAM: 6125.22 MB
Available physical RAM: 5370.3 MB
Total Pagefile: 6123.42 MB
Available Pagefile: 5366.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:686.4 GB) (Free:546.04 GB) NTFS (Disk=0 Partition=3)
Drive e: (Recovery) (Fixed) (Total:12.14 GB) (Free:1.1 GB) NTFS (Disk=0 Partition=1) ==>[system with boot components (obtained from reading drive)]
Drive g: () (Removable) (Total:1.92 GB) (Free:1.86 GB) FAT (Disk=1 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=2) ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 6E98A600)
Partition 1: (Not Active) - (Size=12 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=686 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 2 GB) (Disk ID: 014A0BB3)
Partition 1: (Active) - (Size=2 GB) - (Type=06)
 
 
LastRegBack: 2013-07-02 20:39
 
==================== End Of Log ============================
Link to post
Share on other sites

OK, here you go......this should get you going:

Please download the attached fixlist.txt and copy it to your flashdrive.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options. (as you did before)

Run FRST64 or FRST (which ever one you're using) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

See if the computer boots normally now and if so..........

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
To attach a log if needed:

Bottom right corner of this page.

more-reply-options.jpg

New window that comes up.

choose-files1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot. It's located in the Plugins folder which is in the MBAR folder.

Just run fixdamage.exe.

Verify that they are now functioning normally.

MrC

Link to post
Share on other sites

For get about the RegBack directory , the fix was successful (registry restored):

 

DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.

 

 

When you try to boot up how far does it get?

 

Is it a constant loop??

 

Let me know.....MrC

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.