Win7- Lost access to task manager and explorer.exe


  1. Posts : 3
    Windows 7 Ultimate 32 bit
       #1

    Win7- Lost access to task manager and explorer.exe


    My computer stopped working after getting infected with a virus. I used an Ubuntu live CD with avast to delete all the viruses from my system. But now every time I start my computer, it just shows the background with no taskbar or icons and I can't right click anywhere so I assumed that explorer.exe didn't launch so I pressed Ctrl+alt+delete to try and start task manager to start explorer.exe, but it only gave me the option to lock computer, switch user, log out, or reset password but no task manager. I restarted my computer and chose the repair computer option. From there startup repair didn't do anything and the virus erased all my system restore points so the only option left is the command prompt I tried running sfc /scannow but it returned an error message saying that a system repair is pending and tells me to restart. So I used the command prompt to navigate to the system32 directory and I didn't find taskmgr.exe or explorer.exe so I copied them over from another computer with windows 7 using a flash drive but it still didn't work

    So my situation now is
    -i can't run task manager to start explorer.exe
    -i can't access explorer.exe to try and enable task manager

    So is there a way to enable task manager from the command prompt? Or do I really have to reinstall windows?
      My Computer


  2. Posts : 2,470
    Windows 7 Home Premium
       #2

    SpeedBeast,

    Please try the following...

    Close all windows.

    Press Ctrl Alt Delete (simultaneously).

    A screen displays five options. Select: Start Task Manager

    In the Task Manager, go to the File menu and select: New Task (Run…)

    The Create New Task dialog box appears.

    Type “explorer.exe” (without the quotes) in the Open area.
    Click: OK

    To close the Task Manager, from the File menu, select: Exit Task Manager


    If the above does not work, we need to look deeper...


    Please plug a USB flash drive into a clean computer.
    Go to Start > Computer
    Double-click Computer, and select the flash drive.
    Right-click and select: Format
    Press Start on the Format prompt.
    Remove when done.

    You may want to print these instructions so you can have access to follow
    Also, you may want to read them once before you apply them.

    Go to the Farbar Recovery Scan Tool Download
    Select the download that applies to your system. (32-bit)
    Save the program to the >> USB flash drive.

    Next, plug the flash drive into the problem computer.







    Start the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until the Advanced Boot Options menu appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select your language settings, and click: Next
    • Select your User account and click: OK (If you did not set a password, leave blank.)
    On the System Recovery Options menu you get the following options:
    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Scan your computer's memory for errors
    • Command Prompt
    Select Command Prompt
    • In the Command window, at the blinking cursor type notepad and press: Enter
    • In Notepad, under the File menu select: Open
    • Double-click Computer, find the flash drive letter, remember what letter it is, click on it, and press: Open
    • Close out of Notepad.
    • Click the Command window
    • Type g:\frst.exe, and press: Enter
      Note: Replace the drive letter g with the drive letter of your flash drive!
    • The tool starts and prepares to run. Follow the prompts.
    • Click Yes to the disclaimer.
    • Press: Scan
    When done, the program saves the FRST.txt report, on the flash drive.


    Close Notepad, then, click the Command Prompt window, and type exit, and press: Enter

    Back at the System Recovery Options, press: ShutDown.

    Remove the USB flash drive from the infected computer, and plug it into the good computer.

    Please provide the FRST.txt report, located on the USB flash drive, in your reply.[/
    Last edited by cottonball; 30 Jul 2013 at 22:28.
      My Computer


  3. Posts : 3
    Windows 7 Ultimate 32 bit
    Thread Starter
       #3

    Thanks for your quick reply cottonball! task manager didn't work from the ctrl+alt+delete window so i did the farbar recovery scan tool

    the contents of FRST.txt are



    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04
    Ran by SYSTEM on 31-07-2013 10:42:25
    Running from F:\
    Windows 7 Ultimate (X86) OS Language: English(US)
    Internet Explorer Version 8
    Boot Mode: Recovery

    The current controlset is ControlSet002
    ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [VideoDownloadConverter Search Scope Monitor] - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zsrchmn.exe [126704 2013-07-13] (MindSpark)
    HKLM\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader] - C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbrmon.exe [99728 2013-07-13] (VER_COMPANY_NAME)
    HKLM\...\Run: [0413840] - C:\Windows\l532055.exe [x]
    HKLM\...\Run: [0] - \l.exe [x]
    HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,
    HKLM\...\Winlogon: [Shell] explorer.exe, "C:\Users\mark\AppData\Roaming\Microsoft\Windows\Templates\31413\031413.exe" [x ] ()
    HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
    HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [x]
    HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
    HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [x]
    HKU\mark\...\Run: [HW_OPENEYE_OUC_Zain Broadband] - "E:\Zain Broadband\UpdateDog\ouc.exe" [x]
    HKU\mark\...\Run: [13500550] - C:\Windows\system32\884054545063l.exe [x]
    HKU\mark\...\Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe [ 2013-06-20] (Tonec Inc.)
    HKU\mark\...\Run: [10] - \l.exe [x]
    HKU\mark\...\Policies\system: [DisableTaskMgr] 1
    HKU\mark\...\Policies\system: [DisableRegistryTools] 1
    IMEO\msconfig.exe: [Debugger] C:\Windows\notepad.exe
    IMEO\regedit.exe: [Debugger] C:\Windows\notepad.exe
    AlternateShell: 884054545063l.exe

    ========================== Services (Whitelisted) =================

    S2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [264704 2010-11-16] ()
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
    S0 SharedAccess; C:\Windows\System32\ipnathlp.dll [300544 2009-07-13] (Microsoft Corporation)
    S2 VideoDownloadConverter_4zService; C:\PROGRA~1\VIDEOD~2\bar\1.bin\4zbarsvc.exe [42504 2013-07-13] (COMPANYVERS_NAME)
    S3 ALG; %SystemRoot%\System32\alg.exe [x]
    S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} [x]
    S3 ehRecvr; %systemroot%\ehome\ehRecvr.exe [x]
    S3 ehSched; %systemroot%\ehome\ehsched.exe [x]
    S3 Fax; %systemroot%\system32\fxssvc.exe [x]
    S3 MSDTC; %SystemRoot%\System32\msdtc.exe [x]
    S3 msiserver; %systemroot%\system32\msiexec.exe /V [x]
    S3 RpcLocator; %SystemRoot%\system32\locator.exe [x]
    S3 SNMPTRAP; %SystemRoot%\System32\snmptrap.exe [x]
    S2 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [x]
    S3 VSS; %systemroot%\system32\vssvc.exe [x]
    S3 wbengine; "%systemroot%\system32\wbengine.exe" [x]
    S3 wmiApSrv; %systemroot%\system32\wbem\WmiApSrv.exe [x]
    S2 Zain Broadband. RunOuc; E:\Zain Broadband\UpdateDog\ouc.exe [x]

    ==================== Drivers (Whitelisted) ====================


    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-07-31 10:41 - 2013-07-31 10:41 - 00000000 ___DC C:\FRST
    2013-07-30 23:24 - 2009-07-13 17:14 - 00398336 _____ (Microsoft Corporation) C:\Windows\regedit.exe
    2013-07-30 23:23 - 2009-07-13 17:14 - 00227328 _____ (Microsoft Corporation) C:\Windows\System32\taskmgr.exe
    2013-07-30 23:23 - 2009-07-13 17:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\System32\sfc.exe
    2013-07-30 22:42 - 2013-07-30 22:42 - 03179520 _____ (Microsoft Corporation) C:\Windows\System32\sppsvc.exe
    2013-07-30 22:42 - 2013-07-30 22:42 - 00035840 _____ (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
    2013-07-30 22:40 - 2013-07-30 22:40 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\recdisc.exe
    2013-07-30 22:39 - 2013-07-30 22:39 - 00060928 _____ (Microsoft Corporation) C:\Windows\System32\printui.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\newdev.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00075264 _____ (Microsoft Corporation) C:\Windows\System32\ndadmin.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00047616 _____ (Microsoft Corporation) C:\Windows\System32\csrstub.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\System32\netbtugc.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\bridgeunattend.exe
    2013-07-30 22:37 - 2013-07-30 22:37 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
    2013-07-30 22:34 - 2013-07-30 22:34 - 00070656 _____ (Microsoft Corporation) C:\Windows\System32\MuiUnattend.exe
    2013-07-30 22:33 - 2013-07-30 22:33 - 00144896 _____ (Microsoft Corporation) C:\Windows\System32\iscsicli.exe
    2013-07-30 22:32 - 2013-07-30 22:32 - 00015360 _____ (Microsoft Corporation) C:\Windows\hh.exe
    2013-07-30 22:30 - 2013-07-30 22:30 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\wermgr.exe
    2013-07-30 22:29 - 2013-07-30 22:29 - 00252928 _____ (Microsoft Corporation) C:\Windows\System32\drvinst.exe
    2013-07-30 22:29 - 2013-07-30 22:29 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\dnscacheugc.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\System32\AxInstUI.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\expand.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00020992 _____ (Microsoft Corporation) C:\Windows\System32\sdbinst.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
    2013-07-30 12:55 - 2011-02-24 16:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\System32\explorer.exe
    2013-07-30 12:55 - 2011-02-24 16:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2013-07-29 17:21 - 2013-07-29 17:21 - 00126131 _____ C:\Windows\pending.xml
    2013-07-27 15:00 - 2013-07-27 15:00 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2013-07-27 15:00 - 2013-07-27 15:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2013-07-25 13:18 - 2013-07-30 05:29 - 00000000 ____D C:\ProgramData\IDM
    2013-07-25 13:18 - 2013-07-29 11:30 - 00000000 ____D C:\Users\mark\AppData\Roaming\DMCache
    2013-07-25 13:18 - 2013-07-25 22:56 - 00000000 ____D C:\Users\mark\AppData\Roaming\IDM
    2013-07-25 13:18 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\Downloads\Video
    2013-07-25 13:18 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\Downloads\Compressed
    2013-07-25 13:17 - 2013-07-25 13:19 - 00000000 ___DC C:\Program Files\Internet Download Manager
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\mark\Downloads\mark Porn.exe
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\Default\Downloads\mark Porn.exe
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\Default User\Downloads\mark Porn.exe
    2013-07-23 18:26 - 2013-07-23 18:26 - 00013664 ____N C:\bootsqm.dat
    2013-07-22 05:09 - 2013-07-25 23:54 - 00000000 ____D C:\Windows\System32\appmgmt
    2013-07-21 15:53 - 2013-07-21 15:53 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2013-07-21 13:32 - 2013-07-21 13:32 - 00000000 _RSHC C:\MSDOS.SYS
    2013-07-21 13:32 - 2013-07-21 13:32 - 00000000 _RSHC C:\IO.SYS
    2013-07-17 01:24 - 2013-07-30 05:29 - 00000000 ____D C:\ProgramData\Google
    2013-07-17 01:16 - 2013-07-17 01:16 - 00000000 ____D C:\Users\mark\AppData\Local\Adobe
    2013-07-16 13:18 - 2013-07-28 14:57 - 00001036 _____ C:\Windows\Renungan.html
    2013-07-16 13:18 - 2013-07-28 14:57 - 00000176 _____ C:\Windows\MoonLight.txt
    2013-07-16 13:02 - 2013-07-30 05:45 - 00000000 ___HD C:\Windows\System32\37012a
    2013-07-16 13:02 - 2013-07-30 05:38 - 00000000 _RSHD C:\Windows\03505
    2013-07-16 13:02 - 2013-07-16 13:02 - 00000120 _____ C:\Windows\System32\syscon.sys
    2013-07-15 05:04 - 2013-07-26 01:44 - 00003324 _____ C:\Windows\PFRO.log
    2013-07-13 14:44 - 2013-07-30 05:28 - 00000000 ____D C:\Program Files\Video Download Converter
    2013-07-13 14:43 - 2013-07-23 20:45 - 00000000 ____D C:\Users\mark\AppData\Local\VideoDownloadConverter_4z
    2013-07-13 14:43 - 2013-07-13 14:43 - 00000000 ____D C:\Users\mark\AppData\Local\IAC
    2013-07-13 14:42 - 2013-07-13 14:42 - 00000000 ____D C:\Program Files\VideoDownloadConverter_4z

    ==================== One Month Modified Files and Folders =======

    2013-07-31 10:41 - 2013-07-31 10:41 - 00000000 ___DC C:\FRST
    2013-07-30 22:42 - 2013-07-30 22:42 - 03179520 _____ (Microsoft Corporation) C:\Windows\System32\sppsvc.exe
    2013-07-30 22:42 - 2013-07-30 22:42 - 00035840 _____ (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
    2013-07-30 22:40 - 2013-07-30 22:40 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\recdisc.exe
    2013-07-30 22:39 - 2013-07-30 22:39 - 00060928 _____ (Microsoft Corporation) C:\Windows\System32\printui.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00076800 _____ (Microsoft Corporation) C:\Windows\System32\newdev.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00075264 _____ (Microsoft Corporation) C:\Windows\System32\ndadmin.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00047616 _____ (Microsoft Corporation) C:\Windows\System32\csrstub.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\System32\netbtugc.exe
    2013-07-30 22:38 - 2013-07-30 22:38 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\bridgeunattend.exe
    2013-07-30 22:37 - 2013-07-30 22:37 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
    2013-07-30 22:34 - 2013-07-30 22:34 - 00070656 _____ (Microsoft Corporation) C:\Windows\System32\MuiUnattend.exe
    2013-07-30 22:33 - 2013-07-30 22:33 - 00144896 _____ (Microsoft Corporation) C:\Windows\System32\iscsicli.exe
    2013-07-30 22:32 - 2013-07-30 22:32 - 00015360 _____ (Microsoft Corporation) C:\Windows\hh.exe
    2013-07-30 22:30 - 2013-07-30 22:30 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\wermgr.exe
    2013-07-30 22:29 - 2013-07-30 22:29 - 00252928 _____ (Microsoft Corporation) C:\Windows\System32\drvinst.exe
    2013-07-30 22:29 - 2013-07-30 22:29 - 00028672 _____ (Microsoft Corporation) C:\Windows\System32\dnscacheugc.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\System32\appidpolicyconverter.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\System32\AxInstUI.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\expand.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00020992 _____ (Microsoft Corporation) C:\Windows\System32\sdbinst.exe
    2013-07-30 22:27 - 2013-07-30 22:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\System32\appidcertstorecheck.exe
    2013-07-30 13:26 - 2013-06-28 02:50 - 00004624 _____ C:\Windows\setupact.log
    2013-07-30 11:51 - 2012-12-15 13:50 - 01499240 _____ C:\Windows\WindowsUpdate.log
    2013-07-30 05:46 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\com
    2013-07-30 05:45 - 2013-07-16 13:02 - 00000000 ___HD C:\Windows\System32\37012a
    2013-07-30 05:38 - 2013-07-16 13:02 - 00000000 _RSHD C:\Windows\03505
    2013-07-30 05:37 - 2009-07-13 18:37 - 00000000 ___RD C:\users\Public
    2013-07-30 05:35 - 2012-12-15 04:17 - 00000000 ____D C:\users\mark
    2013-07-30 05:34 - 2012-12-15 10:20 - 00000000 ____D C:\Users\mark\Documents\ROOT
    2013-07-30 05:30 - 2013-03-23 06:24 - 00000000 ____D C:\ProgramData\Zain Broadband
    2013-07-30 05:30 - 2013-02-02 03:17 - 00000000 ____D C:\ProgramData\RealNetworks
    2013-07-30 05:30 - 2013-02-02 03:12 - 00000000 ____D C:\ProgramData\Real
    2013-07-30 05:30 - 2013-01-01 03:11 - 00000000 ____D C:\ProgramData\MobileBrServ
    2013-07-30 05:30 - 2012-12-15 05:01 - 00000000 __SHD C:\Recovery
    2013-07-30 05:30 - 2009-07-13 20:53 - 00000000 ____D C:\users\Administrator
    2013-07-30 05:30 - 2009-07-13 18:37 - 00000000 __RHD C:\users\Default
    2013-07-30 05:29 - 2013-07-25 13:18 - 00000000 ____D C:\ProgramData\IDM
    2013-07-30 05:29 - 2013-07-17 01:24 - 00000000 ____D C:\ProgramData\Google
    2013-07-30 05:29 - 2013-05-31 03:15 - 00000000 ____D C:\ProgramData\Babylon
    2013-07-30 05:29 - 2013-04-11 23:51 - 00000000 ____D C:\ProgramData\McAfee Security Scan
    2013-07-30 05:29 - 2013-04-11 23:51 - 00000000 ____D C:\ProgramData\McAfee
    2013-07-30 05:29 - 2013-03-23 06:20 - 00000000 ____D C:\ProgramData\DatacardService
    2013-07-30 05:29 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Sidebar
    2013-07-30 05:28 - 2013-07-13 14:44 - 00000000 ____D C:\Program Files\Video Download Converter
    2013-07-30 05:28 - 2009-07-13 23:50 - 00000000 ____D C:\Program Files\Windows Journal
    2013-07-30 05:28 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
    2013-07-30 05:14 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\DVD Maker
    2013-07-29 21:15 - 2009-07-13 20:34 - 00016816 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-07-29 21:15 - 2009-07-13 20:34 - 00016816 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-07-29 17:21 - 2013-07-29 17:21 - 00126131 _____ C:\Windows\pending.xml
    2013-07-29 17:18 - 2009-07-13 15:16 - 00064512 _____ (Microsoft Corporation) C:\Windows\System32\hdwwiz.exe
    2013-07-29 11:30 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\AppData\Roaming\DMCache
    2013-07-28 15:38 - 2012-12-15 10:32 - 00000000 ____D C:\Users\mark\AppData\Roaming\vlc
    2013-07-28 14:57 - 2013-07-16 13:18 - 00001036 _____ C:\Windows\Renungan.html
    2013-07-28 14:57 - 2013-07-16 13:18 - 00000176 _____ C:\Windows\MoonLight.txt
    2013-07-27 15:00 - 2013-07-27 15:00 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2013-07-27 15:00 - 2013-07-27 15:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2013-07-27 14:31 - 2013-06-25 06:46 - 00007595 _____ C:\Users\mark\AppData\Local\Resmon.ResmonCfg
    2013-07-26 04:24 - 2012-12-15 05:05 - 00727362 _____ C:\Windows\System32\PerfStringBackup.INI
    2013-07-26 03:28 - 2012-12-16 09:22 - 00000000 ____D C:\Users\mark\AppData\Local\Facebook
    2013-07-26 01:44 - 2013-07-15 05:04 - 00003324 _____ C:\Windows\PFRO.log
    2013-07-25 23:54 - 2013-07-22 05:09 - 00000000 ____D C:\Windows\System32\appmgmt
    2013-07-25 22:56 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\AppData\Roaming\IDM
    2013-07-25 13:19 - 2013-07-25 13:17 - 00000000 ___DC C:\Program Files\Internet Download Manager
    2013-07-25 13:18 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\Downloads\Video
    2013-07-25 13:18 - 2013-07-25 13:18 - 00000000 ____D C:\Users\mark\Downloads\Compressed
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\mark\Downloads\mark Porn.exe
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\Default\Downloads\mark Porn.exe
    2013-07-23 20:45 - 2013-07-23 20:45 - 00000000 _____ C:\Users\Default User\Downloads\mark Porn.exe
    2013-07-23 20:45 - 2013-07-13 14:43 - 00000000 ____D C:\Users\mark\AppData\Local\VideoDownloadConverter_4z
    2013-07-23 20:45 - 2012-12-15 06:39 - 00000000 ____D C:\Users\mark\Downloads\testdisk-6.14-WIP.win
    2013-07-23 18:26 - 2013-07-23 18:26 - 00013664 ____N C:\bootsqm.dat
    2013-07-22 09:29 - 2013-02-02 03:20 - 00000000 ____D C:\Users\mark\AppData\Roaming\Systweak
    2013-07-22 05:09 - 2012-12-15 04:15 - 00000000 ____D C:\Windows\System32\Macromed
    2013-07-21 15:53 - 2013-07-21 15:53 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2013-07-21 13:32 - 2013-07-21 13:32 - 00000000 _RSHC C:\MSDOS.SYS
    2013-07-21 13:32 - 2013-07-21 13:32 - 00000000 _RSHC C:\IO.SYS
    2013-07-17 01:24 - 2012-12-15 04:24 - 00000000 ____D C:\Program Files\Google
    2013-07-17 01:16 - 2013-07-17 01:16 - 00000000 ____D C:\Users\mark\AppData\Local\Adobe
    2013-07-16 13:02 - 2013-07-16 13:02 - 00000120 _____ C:\Windows\System32\syscon.sys
    2013-07-16 13:02 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\system
    2013-07-13 14:43 - 2013-07-13 14:43 - 00000000 ____D C:\Users\mark\AppData\Local\IAC
    2013-07-13 14:42 - 2013-07-13 14:42 - 00000000 ____D C:\Program Files\VideoDownloadConverter_4z

    ==================== Known DLLs (Whitelisted) ============


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION!.
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 37%
    Total physical RAM: 1015.3 MB
    Available physical RAM: 637.29 MB
    Total Pagefile: 1015.3 MB
    Available Pagefile: 636.09 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1926.81 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:11.38 GB) (Free:0.98 GB) NTFS
    Drive e: (SYSTEM) (Fixed) (Total:0.2 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive f: (mark) (Removable) (Total:3.77 GB) (Free:3.76 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: () (Fixed) (Total:137.47 GB) (Free:89.39 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: CD68444D)
    Partition 1: (Active) - (Size=137 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=11 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=201 MB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 4 GB) (Disk ID: 0087D715)
    Partition 1: (Active) - (Size=4 GB) - (Type=0B)


    LastRegBack: 2013-07-15 06:46

    ==================== End Of Log ============================
      My Computer


  4. Posts : 3
    Windows 7 Ultimate 32 bit
    Thread Starter
       #4

    Looking through the log I found out that the userinit.exe is the only thing missing, and after copying that from another computer my computer started running again. Regedit was disabled on my computer so I used the regedit that was supplied with the recovery environment to enable task manager and now everything is running fine. Thanks for the help though, cotton ball.
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #5

    SpeedBeast,

    My apology for the delay.

    As you detected, the userinit.exe was the only thing missing, however, there are other files showing in the FRST report that are not desirable.

    Since you made some modifications the system appears improved, however, we need to dig deeper.

    Please run FRST once again, and post its results.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:12.
Find Us