System Restore - major problem

teckneeculler

Member
Power User
VIP
Local time
8:30 AM
Messages
512
W7 Ultimate 64-bit installed on 1-year-old Apacer 250GB SSD.

Every few days or so, I set a Restore Point. This normally takes about 15 seconds. I ordered one just now and went for a coffee. When I came back about 15 minutes later, the System Restore app was still running.

Odd, I thought.

Button pushes wouldn't stop it so I did Crtl\Alt\Del and stopped it that way.

Tried to set another Restore Point but all the app buttons were greyed out and only returned after I rebooted. So I opened System Restore, intending to revert to the last Restore point, but was told that the system wasn't running and there were no Restore Points anyway!

(Incidentally, I'd had SR limited to about 30GB. But my Apacer 250GB SSD C: drive has plenty of space - 87GB used with 135GB free)

After a few more fruitless attempts I went into Services and changed Volume Shadow Copy from Manual to Auto and did the same with Microsoft Volume Shadow Copy Provider, Windows Installer and a couple of others that I'd read about, along with all their dependencies. Still no joy.

I went into Event Viewer and found that the Volume Shadow Copier had been throwing up an error every 24 hrs since 11th January 2017. Which reminded me that, months ago, I'd set Task Scheduler to run System Restore at midnight.

So I went into Task Scheduler and removed the entry. Rebooted but still no System Restore.

Without going into details, I tried another dozen or so 'fixes' I found here and on other boards, but nothing has changed.

Oh, and I ran the 'vssadmin list writers' command and that found no errors in the 11 or so listed writers.

Plus I've done a full virus check, ran Malwarebytes (full version) twice with no errors, downloaded and ran adwcleaner and rkill with no errors.

I've run sfc /scannow and chkdsk /r twice each. I tried setting an SRP in Safe Mode but the program won't run at all in Safe.

And it couldn't have been a Windows update that caused the problem because Updates has been disabled for eight months.

So I'm kinda stymied. Short of a Windows reinstall I can't think of anything else to do.

Any fresh ideas, guys?

Later: Thought I'd try creating a Restore Point in Safe Mode one more time, so in msconfig I checked 'Start in Safe Mode' and walked away for a while. When I came back, the screen was showing the "Failure configuring Windows updates. Reverting changes. Do not turn off your computer" continuous loop message. And this when I don't even have Windows Updates turned on!

I'm starting to think it's either an as-yet-unknown bug or my SSD C: drive has developed faults.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
My build
OS
Win7 Ultimate SP1
CPU
Intel Core i5 9400 Coffee Lake 14nm
Motherboard
Asus Prime H310M-E R2.0 (LGA1151)
Memory
16G DDR4
Graphics Card(s)
NVidia GeForce GTX 960
Sound Card
Realtek High Definition Audio (mobo)
Monitor(s) Displays
Asus PA248 24" 16:10 format
Screen Resolution
1920x1200@59Hz
Hard Drives
1863GB Seagate ST2000DM
3726GB Seagate ST4000DM
1863GB Seagate ST2000DM
6TB Seagate
465GB NVMe Samsung SSD 970
PSU
750G2
Case
Tower
Cooling
Standard
Keyboard
USB
Mouse
USB
Internet Speed
920Mbs/480Mbs
Antivirus
Malwarebytes
Browser
Firefox
Hi, I would be running a RootKit scanner if I were you.
Kaspersky TDSSKiller.exe is my recommendation.
Virus can and will stop restore points from working.
An added piece of advice.
Don't use restore or Windows backup.
Notoriously unreliable.
Learn Image technologies, Macrium Reflect Free is always recommended here.

Good Luck
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Owner Builder
OS
Windows 7 Ultimate x64 SP1 OEM
CPU
Intel i7 3930K
Motherboard
Asus X79 Deluxe
Memory
Kingston Genesis KHX2133C11D3K4/32G
Graphics Card(s)
Asus RTX 2070 Ti Turbo fan series
Sound Card
Creative Sound Blaster ZXR
Monitor(s) Displays
Samsung U32J39 UHD
Screen Resolution
3840 x 2160
Hard Drives
Samsung 860 Pro 256 GB
OCZ Vertex 4 512GB
Western Digital Black 4TB
PSU
Corsair AX850
Case
Gigabyte
Cooling
Push - Pull 120 mm Noctua PWM, Scythe Big Shuriken 2 Rev. B
Keyboard
Logitech K800 Backlit
Mouse
Logitech MX2 Master
Internet Speed
NBN 25 Mbps
Antivirus
Kaspersky Internet Security
Browser
Mozilla FireFox
Other Info
TP-Link Archer VR600v
Sennheiser TR220 WiFi Head Phones.

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
What anti virus program do you use?

Please list all security programs you have installed.

Do you have any programs by IObit?

Jack
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Thanks guys. Yeah, I'd better run some heavier stuff.

I have a full version of Malwarebytes and ran that several times, but it came up clean. However, if this actually is a bug, it's possible that it's a recent one and might take a while for the fixes to catch up.

I ran RKill and Adwcleaner but they found nil. I'll try TDSSKiller, MeOnMine - used it a few times over the years on customer's machines. Re System Restore, I know that it seems to have an unreliable reputation but I've used it for over 20 years without a problem. Plus, I've taught many customers how to use it and it's got them out of holes. Imaging I think is a PIA. Installed several brands from time to time but never had any success with recovery. I think the best value of apps like Acronis TI (which I just dumped) is the reassurance factor.

Actually, just backing up and restoring the registry is easy and fast. But every now and then you just have to do a reinstall, and I think that's where I'm heading.

Anyway, I'll try a few more bug-fixes first. If I find anything I'll come back.

Oh, and Jack - no, I'm not running any IObit software. Is there a problem with some of their stuff?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
My build
OS
Win7 Ultimate SP1
CPU
Intel Core i5 9400 Coffee Lake 14nm
Motherboard
Asus Prime H310M-E R2.0 (LGA1151)
Memory
16G DDR4
Graphics Card(s)
NVidia GeForce GTX 960
Sound Card
Realtek High Definition Audio (mobo)
Monitor(s) Displays
Asus PA248 24" 16:10 format
Screen Resolution
1920x1200@59Hz
Hard Drives
1863GB Seagate ST2000DM
3726GB Seagate ST4000DM
1863GB Seagate ST2000DM
6TB Seagate
465GB NVMe Samsung SSD 970
PSU
750G2
Case
Tower
Cooling
Standard
Keyboard
USB
Mouse
USB
Internet Speed
920Mbs/480Mbs
Antivirus
Malwarebytes
Browser
Firefox
Heads-up: TDSSKiller found nothing. ComboFix stalled because it couldn't set a Restore Point. Which is kind of ironic :-)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
My build
OS
Win7 Ultimate SP1
CPU
Intel Core i5 9400 Coffee Lake 14nm
Motherboard
Asus Prime H310M-E R2.0 (LGA1151)
Memory
16G DDR4
Graphics Card(s)
NVidia GeForce GTX 960
Sound Card
Realtek High Definition Audio (mobo)
Monitor(s) Displays
Asus PA248 24" 16:10 format
Screen Resolution
1920x1200@59Hz
Hard Drives
1863GB Seagate ST2000DM
3726GB Seagate ST4000DM
1863GB Seagate ST2000DM
6TB Seagate
465GB NVMe Samsung SSD 970
PSU
750G2
Case
Tower
Cooling
Standard
Keyboard
USB
Mouse
USB
Internet Speed
920Mbs/480Mbs
Antivirus
Malwarebytes
Browser
Firefox
Have you tried the GMER (it's in the link I posted) yet tecknee it is fairly heavy weight as you may know and it has found nasties on my machines before - not very often I will admit because things have never been that desperate.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Thanks. Yep, just ran GMER and I'm not sure if what it found is actually a problem.

There was only one entry under the 'Rootkit/Malware' tab:

Type - Thread
Name - C:\Windows\SysWOW64\ntdll.dll[3132:3428]
Value - 0000000000fbe72

Windows Properties show the file to be a Microsoft file, 1.25MB, dated 10Feb16 which is about when I installed W7 last.

Thing that makes me skeptical is that my wife's PC has an identical file. Similar date, I built hers about the same time.

What do you think?

Later: The same file is in my several laptops, too. But none of them are having problems with System Restore.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
My build
OS
Win7 Ultimate SP1
CPU
Intel Core i5 9400 Coffee Lake 14nm
Motherboard
Asus Prime H310M-E R2.0 (LGA1151)
Memory
16G DDR4
Graphics Card(s)
NVidia GeForce GTX 960
Sound Card
Realtek High Definition Audio (mobo)
Monitor(s) Displays
Asus PA248 24" 16:10 format
Screen Resolution
1920x1200@59Hz
Hard Drives
1863GB Seagate ST2000DM
3726GB Seagate ST4000DM
1863GB Seagate ST2000DM
6TB Seagate
465GB NVMe Samsung SSD 970
PSU
750G2
Case
Tower
Cooling
Standard
Keyboard
USB
Mouse
USB
Internet Speed
920Mbs/480Mbs
Antivirus
Malwarebytes
Browser
Firefox
Just change the name of the file and see.
If no change put the name back,
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Owner Builder
OS
Windows 7 Ultimate x64 SP1 OEM
CPU
Intel i7 3930K
Motherboard
Asus X79 Deluxe
Memory
Kingston Genesis KHX2133C11D3K4/32G
Graphics Card(s)
Asus RTX 2070 Ti Turbo fan series
Sound Card
Creative Sound Blaster ZXR
Monitor(s) Displays
Samsung U32J39 UHD
Screen Resolution
3840 x 2160
Hard Drives
Samsung 860 Pro 256 GB
OCZ Vertex 4 512GB
Western Digital Black 4TB
PSU
Corsair AX850
Case
Gigabyte
Cooling
Push - Pull 120 mm Noctua PWM, Scythe Big Shuriken 2 Rev. B
Keyboard
Logitech K800 Backlit
Mouse
Logitech MX2 Master
Internet Speed
NBN 25 Mbps
Antivirus
Kaspersky Internet Security
Browser
Mozilla FireFox
Other Info
TP-Link Archer VR600v
Sennheiser TR220 WiFi Head Phones.

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Hmm. Getting a bit complicated. Says I need permission from 'Trusted Installer'. And changing permissions for Admins and Users is also blocked. Guess I could do it in DOS, but I might just add the task to my list of fixes and try it later.

BTW, there's an 'ntdll.dll.mui' file, which is probably the installer. GMER didn't mention that one. But if it is the installer, and I rename the child file, mightn't the installer try to rebuild it?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
My build
OS
Win7 Ultimate SP1
CPU
Intel Core i5 9400 Coffee Lake 14nm
Motherboard
Asus Prime H310M-E R2.0 (LGA1151)
Memory
16G DDR4
Graphics Card(s)
NVidia GeForce GTX 960
Sound Card
Realtek High Definition Audio (mobo)
Monitor(s) Displays
Asus PA248 24" 16:10 format
Screen Resolution
1920x1200@59Hz
Hard Drives
1863GB Seagate ST2000DM
3726GB Seagate ST4000DM
1863GB Seagate ST2000DM
6TB Seagate
465GB NVMe Samsung SSD 970
PSU
750G2
Case
Tower
Cooling
Standard
Keyboard
USB
Mouse
USB
Internet Speed
920Mbs/480Mbs
Antivirus
Malwarebytes
Browser
Firefox
Back
Top