Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
HELP !!!!! URGENT HELP REQUIRED !
Message
<blockquote data-quote="karthik0812" data-source="post: 511931" data-attributes="member: 52899"><p>thank you for responding, i've doe what you asked, and the fix log is as follows :</p><p></p><p>[code]</p><p>Fix result of Farbar Recovery Scan Tool (x64) Version:25-05-2016 01</p><p>Ran by SYSTEM (2016-05-29 12:39:01) Run:2</p><p>Running from H:\</p><p>Boot Mode: Recovery</p><p>==============================================</p><p></p><p>fixlist content:</p><p>*****************</p><p>createrestorepoint:</p><p>closeprocesses:</p><p>emptytemp:</p><p>C:\WINDOWS\AutoKMS</p><p>HKLM-x32\...\Winlogon: [Userinit] [X]</p><p>HKLM\...\InprocServer32: [Default-wbemess] <==== ATTENTION</p><p>HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] <==== ATTENTION</p><p>HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] <==== ATTENTION</p><p>S2 Change Modem Device Service; "C:\ProgramData\ChgService.exe" -service [X]</p><p>S2 UDisk Monitor; E:\Program Files\Reliance Netconnect+\bin\MonServiceUDisk.exe [X]</p><p>S4 bdselfpr; no ImagePath</p><p>S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]</p><p>S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]</p><p>S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]</p><p>S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]</p><p>S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]</p><p>S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]</p><p>S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]</p><p>S4 vsserv; no ImagePath</p><p>2016-05-22 22:33 - 2013-02-16 21:41 - 00000244 _____ C:\Windows\Tasks\AutoKMSDaily.job</p><p>2016-05-17 01:27 - 2013-02-16 21:41 - 00000244 _____ C:\Windows\Tasks\AutoKMS.job</p><p>HKLM\...\.exe: => <===== ATTENTION</p><p>HKLM\...\exefile\DefaultIcon: <===== ATTENTION</p><p>HKLM\...\exefile\shell\open\command: <===== ATTENTION</p><p>HKU\karthik\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe ",EntryPoint -m l</p><p></p><p>*****************</p><p></p><p>Error: Restore point can only be created in normal mode.</p><p>closeprocesses: => Error: This directive works only outside recovery mode.</p><p>emptytemp: => Error: This directive works only outside recovery mode.</p><p>C:\WINDOWS\AutoKMS => moved successfully</p><p>HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => value restored successfully</p><p>HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\\Default => value restored successfully</p><p>HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => value restored successfully</p><p>HKLM\Software\Classes\CLSID\{7986d495-ce42-4926-8afc-26dfa299cadb}\InprocServer32\\Default => value restored successfully</p><p>Change Modem Device Service => service removed successfully</p><p>UDisk Monitor => service removed successfully</p><p>bdselfpr => service removed successfully</p><p>BstHdDrv => service removed successfully</p><p>ew_hwusbdev => service removed successfully</p><p>huawei_enumerator => service removed successfully</p><p>hwdatacard => service removed successfully</p><p>hwusbdev => service removed successfully</p><p>iSafeKrnlBoot => service removed successfully</p><p>MBAMSwissArmy => service removed successfully</p><p>vsserv => service removed successfully</p><p>C:\Windows\Tasks\AutoKMSDaily.job => moved successfully</p><p>C:\Windows\Tasks\AutoKMS.job => moved successfully</p><p>HKLM\Software\Classes\.exe\\Default => value restored successfully</p><p>HKLM\Software\Classes\exefile\DefaultIcon\\Default => value restored successfully</p><p>HKLM\Software\Classes\exefile\shell\open\command\\Default => value restored successfully</p><p>HKU\karthik\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value removed successfully</p><p></p><p>==== End of Fixlog 12:39:04 ====</p><p>[/code]</p><p>i tried to boot normally, but it still shows the same blue screen error, i really don't wanna lose my data..what do i do now ?</p></blockquote><p></p>
[QUOTE="karthik0812, post: 511931, member: 52899"] thank you for responding, i've doe what you asked, and the fix log is as follows : [code] Fix result of Farbar Recovery Scan Tool (x64) Version:25-05-2016 01 Ran by SYSTEM (2016-05-29 12:39:01) Run:2 Running from H:\ Boot Mode: Recovery ============================================== fixlist content: ***************** createrestorepoint: closeprocesses: emptytemp: C:\WINDOWS\AutoKMS HKLM-x32\...\Winlogon: [Userinit] [X] HKLM\...\InprocServer32: [Default-wbemess] <==== ATTENTION HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] <==== ATTENTION HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] <==== ATTENTION S2 Change Modem Device Service; "C:\ProgramData\ChgService.exe" -service [X] S2 UDisk Monitor; E:\Program Files\Reliance Netconnect+\bin\MonServiceUDisk.exe [X] S4 bdselfpr; no ImagePath S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S4 vsserv; no ImagePath 2016-05-22 22:33 - 2013-02-16 21:41 - 00000244 _____ C:\Windows\Tasks\AutoKMSDaily.job 2016-05-17 01:27 - 2013-02-16 21:41 - 00000244 _____ C:\Windows\Tasks\AutoKMS.job HKLM\...\.exe: => <===== ATTENTION HKLM\...\exefile\DefaultIcon: <===== ATTENTION HKLM\...\exefile\shell\open\command: <===== ATTENTION HKU\karthik\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe ",EntryPoint -m l ***************** Error: Restore point can only be created in normal mode. closeprocesses: => Error: This directive works only outside recovery mode. emptytemp: => Error: This directive works only outside recovery mode. C:\WINDOWS\AutoKMS => moved successfully HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => value restored successfully HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\\Default => value restored successfully HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => value restored successfully HKLM\Software\Classes\CLSID\{7986d495-ce42-4926-8afc-26dfa299cadb}\InprocServer32\\Default => value restored successfully Change Modem Device Service => service removed successfully UDisk Monitor => service removed successfully bdselfpr => service removed successfully BstHdDrv => service removed successfully ew_hwusbdev => service removed successfully huawei_enumerator => service removed successfully hwdatacard => service removed successfully hwusbdev => service removed successfully iSafeKrnlBoot => service removed successfully MBAMSwissArmy => service removed successfully vsserv => service removed successfully C:\Windows\Tasks\AutoKMSDaily.job => moved successfully C:\Windows\Tasks\AutoKMS.job => moved successfully HKLM\Software\Classes\.exe\\Default => value restored successfully HKLM\Software\Classes\exefile\DefaultIcon\\Default => value restored successfully HKLM\Software\Classes\exefile\shell\open\command\\Default => value restored successfully HKU\karthik\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value removed successfully ==== End of Fixlog 12:39:04 ==== [/code] i tried to boot normally, but it still shows the same blue screen error, i really don't wanna lose my data..what do i do now ? [/QUOTE]
Insert quotes…
Verification
Post reply
Top