Jump to content

Please help remove malicious 'Hidden Network' setup on my system.


Recommended Posts

  • Root Admin
3 minutes ago, GANI482 said:

i am using Windows Repair All in One from tweaking.com. 

Please follow the instructions from @kevinf80

However, my own personal opinion is that once you've resorted to using this tool Windows is already too compromised and one should consider backing up their personal data, format the drive, and reinstall Windows.

 

Link to post
Share on other sites

If you are not 100% sure of how the Windows registry works please do not rely on software to make uncertain changes. The errors you quoted are genuine and not associated to Malware.

There are many software programs that claim to be the saviour of the registry, I`ve seen many computers that end up unbootable when they are used.

Personally I would format your hard drive and make a complete fresh install of windows, obviously all imprtant files and data should be backed up first..

Let me know your thoughts..

Edited by kevinf80
Link to post
Share on other sites

I had considered doing this.  Last time I did a fresh install I clicked format for all my drives, and it 'wiped' them empty.  Is this good enough way to do it?  Is it a full overwrite format or does it leave all the data behind that could then carry over if there is something malicious?  I will begin the process of backing things up in the meantime.  

Link to post
Share on other sites

  • Root Admin

Here is an excellent article on doing a clean install of Windows 10 @GANI482

 

Greg Carmack - MVP 2010-2020 -Clean Install Windows 10
https://answers.microsoft.com/en-us/windows/forum/windows_10-windows_install/clean-install-windows-10/1c426bdf-79b1-4d42-be93-17378d93e587

How to Create a Local Account While Setting Up Windows 10
https://www.howtogeek.com/442792/how-to-create-a-local-account-while-setting-up-windows-10/

 

  • Thanks 1
Link to post
Share on other sites

I have completed the fresh windows install.  Sadly though while doing it, it showed my networks, and sure enough the one was the Hidden Network that I was concerned about this whole time.  I did not set it up, nor do I have the password for it.  It was not there months ago.  I have included a picture so you can see for yourself what I am talking about.  I am back to being fully concerned about this issue again.  It clearly shows my ethernet connection on top, my rosie named network that is mine, and the hidden network I have been concerned about this whole time.  My data usage has not been adding up as well, seemingly hundreds of gbs of data every month that was not me, for the past few months.  I have also been watching tv already and seen a message that someone has connected to my tv, via source - internet.  which was not me either.  I have tried resetting the router in the back reset button for example, it still remains.  I have major concerns that this could be a spy network who has access to my lan.  I would feel 1000x safer if you can help me remove the hidden network.  Let me know what you guys think.  Thanks again.

hidden network.JPG

Link to post
Share on other sites

That network is not on your system, that is an SSID being broadcast by a router close to where you live.. Please do not concern yourself, it is nothing to worry about. If you select that network it will ask you for a password, without that you cannot connect...

I assume the network you will use is named rosa420, if so that is the SSID your router is broadcasting. Your neighbours will no doubt also see that network, if you have it password protected they likewise cannot connect to it without the password.

 

Link to post
Share on other sites

I can see me neighbors now on the wifi list, and they are all 1 of zero bars, and they did not show up during the windows install.  I always have airplane mode on on my pc, and just use ethernet connection straight to the router.  My tv and stuff use the wifi though I guess.  When I click the hidden network to connect, its the only one that asks for "Enter the name (SSID) for the network", while all the other ones ask for passwords or security keys.  If i can further try to explain my paranoia on this topic is that, 9 months ago I installed a pirate software, it installed some sort of system driver.  sure enough i then read the torrent comments of people saying, 'this set up a hidden network on my system and has been using a tb a month in data, survived reinstalls, and that it was very hard to remove and how they solved it was by wiping their drives with some sort of external driver wiper software loaded onto a usb drive.  So I check my wifi list then and sure enough originally discovered the hidden network.  A different person on another site said they had the same problem and thats actually what led me to using that Windows Repair All-in-One.  That person said - 

"The above tool is not some crappy gimmick tool as it appears, its the real deal. In my case, the standard DISM / SFC Repairs were not working, even after multiple fresh installs of windows , the "malware" survived , as i had persistent problems. This tool actually reverts everything forcefully back to the original/default - such as: file/owner permissions, registry permissions and default registry values, verifies digital signatures of all windows components, Reparse points etc.

Some 'malware' even extends to windows services. For example, if you type 'sevices.msc' in the search bar, you can launch the services panel. Here, you can see all the windows services. There is a column named 'log on as'. Some services are local services, and some are network services. Malicious actors can hijack system services and change the log on user - this tool can help with that too, and optionally, you can revert any affected services manually by changing the 'log on as' to NT AUTHORITY / Local service (password blank). (NOTE: not all services are supposed to be local services, im just giving you an example).

OFF TOPIC: in reference to the above, please note: i didn't have a 'virus' > kaspersky could not detect anything, malwarebytes nothing, hitmanpro, tdskiller (kaspersky rootkit tool). I had an issue with a malicious actor which gained access to my network, and this tool really helped - i suspect on every new install the old 'settings' were restored somehow.

Along with this tool, i used GPARTED to remove any HPA hidden partition in all hard drives using the terminal and some special commands. Changing my HDD's UUID's, resizing/moving partitions/sectors left/right to re-allign them and overwrite what was hidden/stored. Testdisk also helped by alerting me to detected hidden partition (HPA) , and sector mismatches on all my drives. And ofcourse, in a scenario like this, nuking and replacing the router with a PFSENSE."

 

Maybe that guy is an idiot also, but the things he was describing seemed exactly what I was worried about.  I never tried using those programs he is talking about to detect 'hidden partitions' though.  While formatting my 2 storage hds right now, I see that my C drive has partitions that skip from partition 1 to partition 4 for C, which are normal windows partitions, but why would it not show partitions 2 and 3?  

You will never understand how helpful it is that you are listening to my paranoia, because I actually stressed over this for several months alone before trying these sort of websites to get help with it.  Paranoia brain says 'missing partition numbers and a hidden network on my list, oh my, this all adds up to what i been saying' sort of thinking.  I also worry that I was never able to fully rewrite over format the C drive like I am right now with my other 2 drives.  Like sure I did delete all partitions from C, and click format on the windows install, but i dont think that overwrites everything like id feel safer about.  I do very much appreciate it.  

parts.PNG

Link to post
Share on other sites

Arris Touchstone Model:CM8200A .  I found some strange things in my windows credentials manager.  There were several virtualapp/didlogical , sso pop user, sso pop device type things with credentials set up.  I deleted them but got a screenshot of one of the things.  There was more but I deleted them before taking the screenshot.  I suspect maybe they come over when I sync'd my edge with my windows account but I am not sure.  Could this be malicious?  That is not one of my user names or anything.

Capture.PNG

Edited by AdvancedSetup
corrected font issue
Link to post
Share on other sites

  • Root Admin

While you wait for @kevinf80 @GANI482 please provide the make and model of your computer and if desktop or laptop

 

Please download HWiNFO the Professional System Information and Diagnostics program.
HWiNFO Portable for Windows

Unzip the program to its own folder such as: C:\HWiNFO
Go to the new folder and locate the file C:\HWiNFO\HWiNFO64.exe and double-click to run it.
Click the RUN button.
Ignore the update, click close.
Click on Save Report and choose HTML and click Next, then Finish
By default, it will create a new report named COMPUTER.HTM in the same folder as the program. C:\HWiNFO
Please zip that file and attach it to your next reply

Thank you

Link to post
Share on other sites

Hiya GANI482,

Do the following, select your wifi icon, that will bring up the SSID broadcast list. Select the Hidden Network entry, select "Connect" you will be asked for the network name, not the password. Type in rosa420 are you now given the option to type in "Network security key" if so just cancel out... That sort of proves the Hidden network is actually a broadcast from your own router. I`ve just check my own system that way... I then googled for the instructions to remove that entry (Broadcast) for my router "Virgin Hub 3" followed those instructions and bingo, hidden network entry disappeared after rebooting the router and PC...

Regards,

Kevin

Link to post
Share on other sites

make and model of your computer and if desktop or laptop = I custom built this pc myself so no make or model.  it is a desktop pc.  

I have included the HWiNFO log requested.

I did the test by typing in "rosa420", and it did take me to the network security thing and I canceled it out.  I also tested it by typing in "sandwich" which also took me to the network security screen as well so it seems like can type anything.  I feel 99% sure though that it is from my router so we should still attempt that repair you said about that worked for you, just so I feel better with the hidden network gone.

Thanks so much from the two of you.  I feel like we are very very close to having this solved now.

HWiNFO.zip

Edited by AdvancedSetup
corrected font issue
Link to post
Share on other sites

  • Root Admin

@kevinf80 Had done all the excellent work in getting you fixed up.

 

Please double-check and see if there are any updates for your Motherboard from Asrock
https://www.asrock.com/MB/Intel/Z270 Killer SLIac/index.asp


Your current video card drivers look to be a bit old. If you don't really play games perhaps updating not as critical

Current NVIDIA Drivers
Driver Description:    NVIDIA GeForce GTX 1060 6GB
Driver Provider:    NVIDIA
Driver Version:    27.21.14.5671 (GeForce 456.71)
Driver Date:    29-Sep-2020


GEFORCE GAME READY DRIVER from Nvidia
 
Version:    471.96  WHQL
Release Date:    2021.8.31
Operating System:    Windows 10 64-bit, Windows 11
Language:    English (US)
File Size:    720.56 MB

https://www.nvidia.com/Download/index.aspx?lang=en-us

 

 

Please download the following software and run it to check for other program updates for your computer.

Patch My PC Home Updater
https://patchmypc.com/home-updater

 

 

Link to post
Share on other sites

Oddly enough I just installed that new nvidia driver today after the fresh install, the old one was from windows update.  Not sure why the new one would not be showing up, maybe I installed it right after running that hwid, but either way I will reinstall the latest driver to be sure.  

I ran that patch my pc and it says everything is up to date.

I have all the installers off the official asrock site I keep on my external for when I do fresh reinstalls.  I will finish installing them all now.  They do not effect the hidden network though because I had them all before this fresh install.

I am worried this ISP provided arris router is so crap the hidden network might not be removeable, but I will wait and see how Kevin did his.

patch.PNG

Link to post
Share on other sites

  • Root Admin

I do hope you're performing good, solid backups of your computer. The use of P2P Torrenting software has been the cause of many ransomware infections of late.

The act of torrenting itself is not illegal. However, downloading and sharing unsanctioned copyrighted material is very much illegal, and there is always a chance of getting caught by the authorities.
Torrenting non-copyrighted material is perfectly fine and is allowed. We have seen an increase in malware being bundled with software downloads over P2P.
Please keep in mind when sharing files that you're increasing the risk that your system might get infected. Scan all files prior to running them.

Also, note that most computer experts no longer recommend the use of CCleaner. The choice is yours though 😁

Cheers

 

Link to post
Share on other sites

Hiya GANI482,

These are settings changes for my router to get rid of hidden network, obviously your router is totally different so you will need to d/l the manual for your router from manufacturer website..

Instructions for Virgin Hub 3 router

Log in to the Hub. open tab in browser, type in 192.168.0.1 hit enter. Type in password hit enter to open the hub, from there do the following:

Advanced Settings > Wireless Signal > click ‘Disable Channel Optimization’ > Click ‘Apply Changes’.

Advanced Settings > Wireless > Security > Add 2 to the 2.4GHz Channel name > Add 5 to the 5 GHz Channel name > Click ‘Apply Changes’

Advanced > Settings> Wireless > Guest Network > Disable Guest Network > Click ‘Apply Changes’

You can leave the passwords the same as they are. 

Log out of the Hub.

You will need to reconnect all you Wi-Fi devices some will want to connect to 5Ghz and some to 2.4GHz and some will connect to either.

2.4GHz is a stronger signal but slower than 5GHz so if you have problems on 5GHz change to 2.4GHz.

Another quicker fix (supposedly) never tried it myself. Use the access pinhole to factory reset the router, for mine with router powered on push in reset button through pinhole, hold in for 10 seconds then release. Router will then run a full reset to factory settings. Obviously password etc will revert to originals...

Thanks,

Kevin.

Link to post
Share on other sites

Unfortunately this routers page doesnt have any changeable options.  Its manual says "Note: The configuration settings on the CM8200 Configuration screen are read-only and cannot be modified. You will have to contact your service provider to obtain special authorization to change the cable modem frequencies and other configuration settings."  I will try to contact the ISP and hope they understand what I am talking about.  Thank you.

Link to post
Share on other sites

Hiya GANI482,

I really would not be concerned with Hidden Network Entry, it is a broadcast from your own router. Removing that entry is only a cosmetic change and makes no difference whatsoever.

One good thing that did come out of this exercise, my ISP has indicated a router upgrade is available to me for free. I did contact them regarding the hidden network debacle, after giving all requested information to them the offer was made...

Maybe your ISP will make an upgrade available to you...

Regards,

Kevin.

Link to post
Share on other sites

Thank you.  I am more convinced now than ever that it is not malicious or being used by strangers to spy on me or something.  Also the fact that my routers setting are read only, leads me to believe that even if someone wanted to, they could not have accessed my router anyways to make any changes at all.  This was beyond helpful.  Had I not come here I just would have likely worried about it forever.  You guys provide a great service here.  Having someone listen to all your concerns not only helps computers but it helps the people too.  I feel better, and you got a router upgrade, id say we are both winners today.  I think I will take the weekend off from worrying about this pc for once, and contact my ISP monday.  Cheers to everyone involved and to this great service.  

Link to post
Share on other sites

I decided I should run dism sfcscan fistlist from earlier on my new fresh windows install before I let this thread close, and sadly it found errors on my new install.  Much like that other persons first hand account I posted earlier where guy said "In my case, the standard DISM / SFC Repairs were not working, even after multiple fresh installs of windows , the "malware" survived , as i had persistent problems."  Sadly I am worried again as how can this be?

Fixlog.txt

Link to post
Share on other sites

2021-09-17 06:56:33, Info CBS Session: 30911410_2912798412 initialized by client WindowsUpdateAgent, external staging directory: (null), external registry directory: (null)

2021-09-17 06:56:33, Info CBS InternalOpenPackage failed for Package_for_KB3025096~31bf3856ad364e35~amd64~~6.4.1.0 [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to internally open package. [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to create open package. [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to OpenPackage using worker session [HRESULT = 0x800f0805]

2021-09-17 06:56:33, Info CBS Session: 30911410_2912813540 initialized by client WindowsUpdateAgent, external staging directory: (null), external registry directory: (null)

2021-09-17 06:56:33, Info CBS InternalOpenPackage failed for Package_for_KB3025096~31bf3856ad364e35~x86~~6.4.1.0 [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to internally open package. [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to create open package. [HRESULT = 0x800f0805 - CBS_E_INVALID_PACKAGE]

2021-09-17 06:56:33, Info CBS Failed to OpenPackage using worker session [HRESULT = 0x800f0805]

2021-09-17 06:56:34, Info CBS WU creates the package, AppID:MoUpdateOrchestrator, UpdateID:{33D6CF13-224E-459B-AD4F-AF8C5E3CC469}, revision: 202

2021-09-17 06:56:34, Info CBS Read out cached applicability from TiLight for package: Mapping_Package_for_KB3089226_af-ZA_amd64~31bf3856ad364e35~amd64~~10.0.10240.0, ApplicableState: 0, CurrentState:0

2021-09-17 06:56:34, Info CBS WU creates the package, AppID:MoUpdateOrchestrator, UpdateID:{1103CC99-E96C-4F7C-885C-A67A975ECBEE}, revision: 200

2021-09-17 06:56:34, Info CBS Read out cached applicability from TiLight for package: Package_for_DotNetRollup~31bf3856ad364e35~amd64~~10.0.4400.1, ApplicableState: 112, CurrentState:112

2021-09-17 06:58:35, Info CBS Trusted Installer is shutting down because: SHUTDOWN_REASON_AUTOSTOP

2021-09-17 06:58:35, Info CBS TiWorker signaled for shutdown, going to exit.

2021-09-17 06:58:35, Info CBS Deleting the contents of directory: \\?\C:\Windows\CbsTemp

2021-09-17 06:58:35, Info CBS Deletion of: \\?\C:\Windows\CbsTemp successful

2021-09-17 06:58:35, Info CBS CbsCoreFinalize: ExecutionEngineFinalize

 

021-09-17 06:46:41, Info CSI 000001b9 [SR] Beginning Verify and Repair transaction

2021-09-17 06:46:41, Info CSI 000001ba Warning: Overlap: Directory \??\C:\Program Files (x86)\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:41, Info CSI 000001bb Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:41, Info CSI 000001bc Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:41, Info CSI 000001bd Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch Host= amd64 Guest= x86, nonSxS, pkt {l:8 b:31bf3856ad364e35}

 

2021-09-17 06:46:32, Info CSI 00000184 [SR] Beginning Verify and Repair transaction

2021-09-17 06:46:33, Info CSI 00000185 Warning: Overlap: Directory \??\C:\Windows\SysWOW64\drivers\en-US\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:33, Info CSI 00000186 Warning: Overlap: Directory \??\C:\Windows\SysWOW64\wbem\en-US\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:33, Info CSI 00000187 Warning: Overlap: Directory \??\C:\Windows\help\mui\0409\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch Host= amd64 Guest= x86, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

 

2021-09-17 06:46:08, Info CSI 00000100 [SR] Beginning Verify and Repair transaction

2021-09-17 06:46:08, Info CSI 00000101 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:08, Info CSI 00000102 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:46:08, Info CSI 00000103 Warning: Overlap: Directory \??\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-shell32, version 10.0.19041.1202, arch amd64, nonSxS, pkt {l:8 b:31bf3856ad364e35}

 

2021-09-17 06:45:42, Info CSI 00000080 [SR] Beginning Verify and Repair transaction

2021-09-17 06:45:43, Info CSI 00000081 Warning: Overlap: Directory \??\C:\Windows\System32\drivers\en-US\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:45:43, Info CSI 00000082 Warning: Overlap: Directory \??\C:\Windows\System32\wbem\en-US\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

2021-09-17 06:45:43, Info CSI 00000083 Warning: Overlap: Directory \??\C:\Windows\help\mui\0409\ is owned twice or has its security set twice

Original owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

New owner: Microsoft-Windows-Foundation-Default-Security.Resources, version 10.0.19041.1, arch amd64, culture [l:5]'en-US', nonSxS, pkt {l:8 b:31bf3856ad364e35}

 

2021-09-17 06:45:17, Info CBS Seconds between initial corruption detections: -1

2021-09-17 06:45:17, Info CBS Seconds between corruption and repair: -1

2021-09-17 06:45:17, Info CBS Reboot mark cleared

2021-09-17 06:45:17, Info CBS Winlogon: Simplifying Winlogon CreateSession notifications

2021-09-17 06:45:17, Info CBS Winlogon: Deregistering for CreateSession notifications

2021-09-17 06:45:17, Info CBS Exec: Processing complete, session(Corruption Repairing): 30911408_3668031720 [HRESULT = 0x00000000 - S_OK]

2021-09-17 06:45:17, Info CBS Session: 30911408_3668031720 finalized. Reboot required: no [HRESULT = 0x00000000 - S_OK]

2021-09-17 06:45:17, Info CBS Deleting directory: \\?\C:\Windows\CbsTemp\30911408_3668031720\

2021-09-17 06:45:17, Info CBS Moving directory from \\?\C:\Windows\CbsTemp\30911408_3668031720\ to \\?\C:\Windows\CbsTemp\30911408_3668031720\{85EFA854-E023-4346-9E10-6D70451F4518}

2021-09-17 06:45:17, Info CBS Failed to move \\?\C:\Windows\CbsTemp\30911408_3668031720\ to temp directory \\?\C:\Windows\CbsTemp\30911408_3668031720\{85EFA854-E023-4346-9E10-6D70451F4518} [HRESULT = 0x80070020 - ERROR_SHARING_VIOLATION]

2021-09-17 06:45:17, Info CBS Failed moving directory: \\?\C:\Windows\CbsTemp\30911408_3668031720\ to temp, will delete in-place instead [HRESULT = 0x80070020 - ERROR_SHARING_VIOLATION]

2021-09-17 06:45:17, Info CBS Deletion of: \\?\C:\Windows\CbsTemp\30911408_3668031720\ successful

2021-09-17 06:45:17, Info CBS Session: 30911409_443880694 initialized by client DISM Package Manager Provider, external staging directory: (null), external registry directory: (null)

2021-09-17 06:45:17, Info CBS TiWorker: Client requests SFP repair object.

2021-09-17 06:45:17, Info CSI 0000000e@2021/9/17:10:45:17.341 WcpInitialize: wcp.dll version 10.0.19041.1220 (WinBuild.160101.0800)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.