Jump to content

Recommended Posts

15 minutes ago, daniel43 said:

Since a few months now my disk backup stops working. Closing Malwarebytes premium and restarting Aomei backupper does the job.

Please do the following so that we may take a closer look at your installation for troubleshooting:

NOTE: The tools and the information obtained is safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

 

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to your desktop, please upload that file on your next reply

Thanks

Link to post
Share on other sites

  • Root Admin

Hello @daniel43

The logs indicate that your system is having issues with the Intel Rapid Storage Driver and Manager as well.

It is also having VSS (Volume Shadow Copy) errors. All of which will cause issues running any backup software.

 

Error: (01/31/2022 04:23:14 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service Error: Unexpected error executing a query for the IVssWriterCallback interface. hr = 0x80070005, Access Denied.
.
This is often caused by incorrect security settings in the writer or requestor process.


Editing:
   Collecting Writer Data

context:
   Writer Class ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Author Instance ID: {6e762c26-cb47-4e75-bbcf-315409fd8827}

Error: (01/31/2022 04:22:58 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service Error: Unexpected error executing a query for the IVssWriterCallback interface. hr = 0x80070005, Access Denied.
.
This is often caused by incorrect security settings in the writer or requestor process.


Editing:
   Collecting Writer Data

context:
   Writer Class ID: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Author Instance ID: {6e762c26-cb47-4e75-bbcf-315409fd8827}

Error: (01/31/2022 03:09:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Error Application Name: IAStorDataMgrSvc.exe, Version: 15.5.0.1051, Timestamp: 0x58cbf387
Error module name: unknown, version: 0.0.0.0, timestamp: 0x00000000
Exception Code: 0xc0000005
Margin of Error: 0x04d0b041
Error ID: 0xebc
Application start time with error: 0x01d816abfe597363
Faulting application path: C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report ID: 3b075a00-2af1-4285-a9f9-bbbf544ace95
Full package name with error:
Relative application ID of package with error:

Error: (01/31/2022 03:09:02 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Information: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__12_0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (01/31/2022 02:12:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Error Application Name: IAStorDataMgrSvc.exe, Version: 15.5.0.1051, Timestamp: 0x58cbf387
Error module name: unknown, version: 0.0.0.0, timestamp: 0x00000000
Exception Code: 0xc0000005
Margin of Error: 0x0533a979
Error process ID: 0xf70
Application start time with error: 0x01d816a40ac28f09
Faulting application path: C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
Faulting module path: unknown
Report ID: f9a1a2ea-9475-4398-b776-d091da32e3a7
Full package name with error:
Relative application ID of package with error:

Error: (01/31/2022 02:12:09 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: IAStorDataMgrSvc.exe
Framework version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Information: System.NullReferenceException
   at IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   at IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   at IAStorDataMgr.EventRelay.<Start>b__12_0(System.Object)
   at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()
   at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

 

 

Let's go ahead and try to do some generic clean-up and see if that helps.

 

Please download the attached fixlist.txt file and save it to the Desktop or location where you ran FRST from.
NOTE. It's important that both files, FRST or FRST64, and fixlist.txt are in the same location or the fix will not work.

Please make sure you disable any real-time antivirus or security software before running this script. Once completed, make sure you re-enable it.

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone.

Run FRST or FRST64 and press the Fix button just once and wait.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop (Fixlog.txt) or wherever you ran FRST from. Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.

NOTE-1:  This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will also run a disk check on the restart to ensure disk integrity. Depending on the speed of your computer this fix may take 30 minutes or more.

NOTE-2: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications will be automatically closed. Also, make sure you know the passwords for all websites as cookies will also be removed. The use of an external password manager is highly recommended instead of using your browser to store passwords.

NOTE-3: As part of this fix it will also reset the network to default settings including the firewall. If you have custom firewall rules you need to save please export or save them first before running this fix.

The following directories are emptied:

  • Windows Temp
  • Users Temp folders
  • Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
  • Recently opened files cache
  • Flash Player cache
  • Java cache
  • Steam HTML cache
  • Explorer thumbnail and icon cache
  • BITS transfer queue (qmgr*.dat files)
  • Recycle Bin

Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix.

The system will be rebooted after the fix has run.

fixlist.txt

Thanks

 

Link to post
Share on other sites

  • Root Admin

Thank you @daniel43 please run through the following 3 steps for me and we'll make sure we don't find any type of infections.

From the current log which is a good thing.

Windows Resource Protection found corrupt files and successfully repaired them.

 

 

Please run the following steps and post back the logs as an attachment when ready.
Temporarily disable your antivirus or other security software first. Make sure to turn it back on once the scans are completed.
Temporarily disable Microsoft SmartScreen to download software below if needed. Make sure to turn it back on once the scans are completed.
If you still have trouble downloading the software please click on Reveal Hidden Contents below for examples of how to allow the download.

 

Spoiler
 
 
 
 
Spoiler

When downloading with some browsers you may see a different style of screens that may block FRST from downloading. The program is safe and used hundreds of times a week by many users.

Example of Microsoft Edge blocking the download

image.png

image.png

image.png

 



STEP 01

  • If you already have Malwarebytes installed then open Malwarebytes and click on the Scan button. It will automatically check for updates and run a Threat Scan.
  • If you don't have Malwarebytes installed yet please download it from here and install it.
  • Once installed then open Malwarebytes and select Scan and let it run.
  • Once the scan is completed make sure you have it quarantine any detections it finds.
  • If no detections were found click on the Save results drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If there were detections then once the quarantine has completed click on the View report button, Then click the Export drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If the computer restarted to quarantine you can access the logs from the Detection History, then the History tab. Highlight the most recent scan and double-click to open it. Then click the Export drop-down, then the Export to TXT  button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If Malwarebytes won't run then please skip to the next step and let me know in your next reply that the scanner would not run.

STEP 02

Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Double-click to run the program
  • Accept the End User License Agreement.
  • Wait until the database is updated.
  • Click Scan Now.
  • When finished, if items are found please click Quarantine.
  • Your PC should reboot now if any items were found.
  • After reboot, a log file will be opened. Attach or Copy its content into your next reply.

RESTART THE COMPUTER Before running Step 3

STEP 03
Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a check mark here each time
  • Please attach the Additions.txt log to your reply as well.
  • On your next reply, you should be attaching frst.txt and additions.txt to your post, every time.

 

Thanks

Link to post
Share on other sites

  • Root Admin

Hello @daniel43

Did you enable the Shared PC service on this system?

Please open an elevated admin command prompt and copy / paste the following, one line at a time, and press the Enter key and post back the results.

 

sc qc shpamsvc 


sc queryex shpamsvc

 

Then please download the following from Intel and save the zip file to your computer.

Intel® Management Engine Drivers for Windows 7*, Windows 8.1* and Windows® 10
https://www.intel.com/content/www/us/en/download/682431/intel-management-engine-drivers-for-windows-7-windows-8-1-and-windows-10.html

Then extract the files and folders and go into the ME_SW_DCH folder and run the SetupME.exe installer.

image.png

image.png

 

Then restart the computer and run the Farbar program again and click the SCAN button and get me a new set of logs please.

  • FRST.txt
  • Addition.txt

 

Thank you

 

 

 

Link to post
Share on other sites

  • Root Admin

It doesn't look like that was too helpful unfortunately @daniel43

Please restart the computer one more time and then run the following

 

SecurityCheck by glax24              

I would like you to run a tool named SecurityCheck to inquire about the current security update status of some applications.

  • Download SecurityCheck by glax24: https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe
  • If Microsoft SmartScreen blocks the download, click through to save the file
  • This tool is safe.   Smartscreen is overly sensitive.
  • If SmartScreen blocks the file from running click on More info and Run anyway
  • Right-click  with your mouse on the Securitycheck.exe  and select "Run as administrator"  and reply YES to allow to run & go forward
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file.  Attach it with your next reply.
  • You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt

 

image.png

image.png

image.png

 

Thank you

 

 

Link to post
Share on other sites

  • Root Admin

Okay, let me have you run the following then @daniel43

 

Please download and run the following Kaspersky Virus Removal Tool 2020 and save it to your Desktop.

(Kaspersky Virus Removal Tool version 20.0.10.0 was released on November 9, 2021)

Download: Kaspersky Virus Removal Tool

How to run a scan with Kaspersky Virus Removal Tool 2020
https://support.kaspersky.com/15674

How to run Kaspersky Virus Removal Tool 2020 in the advanced mode
https://support.kaspersky.com/15680

How to restore a file removed during Kaspersky Virus Removal Tool 2020 scan
https://support.kaspersky.com/15681

 


Select the  image.png  Windows Key and R Key together, the "Run" box should open.

user posted image

Drag and Drop KVRT.exe into the Run Box.

user posted image

C:\Users\{your user name}\DESKTOP\KVRT.exe will now show in the run box.

image.png

add -dontencrypt   Note the space between KVRT.exe and -dontencrypt

C:\Users\{your user name}\DESKTOP\KVRT.exe -dontencrypt should now show in the Run box.
 
image.png


That addendum to the run command is very important, when the scan does eventually complete the resultant report is normally encrypted, with the extra command it is saved as a readable file.

Reports are saved here C:\KVRT2020_Data\Reports and look similar to this report_20210123_113021.klr
Right-click direct onto that report, select > open with > Notepad. Save that file and attach it to your reply.

To start the scan select OK in the "Run" box.

A EULA window will open, tick all confirmation boxes then select "Accept"

image.png

In the new window select "Change Parameters"

image.png

In the new window ensure all selection boxes are ticked, then select "OK" The scan should now start...

user posted image

When complete if entries are found there will be options, if "Cure" is offered leave as is. For any other options change to "Delete" then select "Continue"

user posted image

When complete, or if nothing was found select "Close"

image.png

Attach the report information as previously instructed...
 
Thank you
 
 

 

 

Link to post
Share on other sites

  • Root Admin

That's good. Kaspersky did not find any infections

Let me have you run the following please. @daniel43

 

 

Please download the following tool

Farbar Service Scanner and run it on the computer with the issue
http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/

 

Make sure the following options are checked:

  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center/Action Center
  • Windows Update
  • Windows Defender

Click "Scan"

It will create a log (FSS.txt) in the same directory the tool is run.
Please attach the log to your next reply.

 

Link to post
Share on other sites

  • Root Admin

Please uninstall the following program from the Control Panel

Java 8 Update 311 (64-bit)

 

You're still having an error with the Intel Rapid Storage Technology.

 

Application errors:
==================
Error: (02/08/2022 03:09:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: IAStorDataMgrSvc.exe, versie: 15.5.0.1051, tijdstempel: 0x58cbf387
Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode: 0xc0000005
Foutmarge: 0x049fa979
Id van proces met fout: 0x2d0
Starttijd van toepassing met fout: 0x01d81cf55c9cf76c
Pad naar toepassing met fout: C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
Pad naar module met fout: unknown
Rapport-id: 69db79db-8e11-401d-8040-b6bb93fa6744
Volledige pakketnaam met fout:
Relatieve toepassings-id van pakket met fout:

Error: (02/08/2022 03:09:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Toepassing: IAStorDataMgrSvc.exe
Framework-versie: v4.0.30319
Beschrijving: het proces is beëindigd als gevolg van een onverwerkte uitzondering.
Uitzonderingsinformatie: System.NullReferenceException
   bij IAStorUtil.SystemDataModelListener.ProcessSystemDataModelChanges()
   bij IAStorUtil.SystemDataModelListener.LoadSavedSystemState()
   bij IAStorDataMgr.EventRelay.<Start>b__12_0(System.Object)
   bij System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   bij System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bij System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bij System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   bij System.Threading.ThreadPoolWorkQueue.Dispatch()
   bij System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

 

 

Please see if you're able to update the .NET Framework or not. Visit the link below and there should be a RUNTIME link for the latest OFFLINE version. See if it will allow you to reinstall it and let me know.

Download .NET Framework 4.8 Runtime
https://dotnet.microsoft.com/en-us/download/dotnet-framework/net48

Offline installer: https://go.microsoft.com/fwlink/?linkid=2088631

 

Link to post
Share on other sites

Hello,

I deleted Java 8 update 311 (64-bit)

I do not understand what you want me to do with .net ?

1) On 12th jan 2022, via  windows update, .net framework 48 was installed on my pc : should  I reinstall the downloaded ndp48-x86-x64-all...exe file ? This is no update.

2) I downloaded the .net 6.0.1 runtime  but I wait to try reinstalling until I got more instructions from you.

Best regards

 

 

Link to post
Share on other sites

  • Root Admin

I'm hoping that possibly something is wrong with your .NET framework installation that maybe a reinstall may fix. The Intel software keeps faulting for some reason with .NET

The file name I get when I download the offline installer is:   ndp48-x86-x64-allos-enu.exe

I'd like you to try either a reinstall or repair if offered and see if that makes any change and stops the faulting from happening.

 

Link to post
Share on other sites

Hello,

Reinstalling ( as admin) ndp48-x86-x64-altos-emu.exe resulted into message  ".net framework 4.8 update is already installed" (free translation)

Discovered a repair tool for .Net Framework : https://docs.microsoft.com/en-us/dotnet/framework/install/repair

Running ".NET Framework Repair Tool" (as admin) give following reaction : see knipsel net1.png

Applied recommended changes give following reaction : see knipsel net2.png

Reinstalled ndp48-x86-x64-altos-emu.exe give following reaction : see knipsel net3a&b

Run dotnet-runtime-6.0.1-win-x64.exe see item 2 of my previous message without problems

Awaiting further instructions

Best regards

 

 

 

Knipsel net3b.PNG

Knipsel net3a.PNG

Knipsel net2.PNG

Knipsel net1.PNG

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.