New
#91
Try this one instead....
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\XiaobaiFsForXP /S
Try this one instead....
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\XiaobaiFsForXP /S
Hi, the above command is also unable to find the details.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\XiaobaiFsF
orXP /S
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>
Hmm - OK, we'll try a twofer, then...
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_XiaobaiFsForXP /S
REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_XiaobaiFs /S
The above methods also didn't work.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Xia
obaiFsForXP /S
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>REG QUERY HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Xia
obaiFs /S
ERROR: The system was unable to find the specified registry key or value.
C:\windows\system32>
Looks like we'll have to do a search for it -
BE CAREFUL! registry cock-ups can be very difficult to cure, and there is no 'Undo' option!
Open Regedit.
click on the Computer icon to highlight it
Click on the Edit option in the toolbar, and select Find..
in the box, type
XiaobaiFs
make sure that the three 'Look at' boxes are ticked, and the 'Match whole string..' is unticked, then click 'Find Next'
make a note of the first entry - if you right-click on the key name in the left panel, and select Copy Key, you can paste it into Notepad for safekeeping, and add any value name afterward.
Hit F3 to continue searching (note that if it finds a value or data, and you've clicked on the Key name, it will find the same entry again, so you'll need to F3 twice.
continue until you get a 'reached end of registry'message, and post your results.
Found it! :)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\System\XiaobaiFs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\XiaobaiFs\Instances
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\XiaobaiFs\Instances\XiaobaiFs - Top Instance
...but there's no instance in CurrentControlSet? the ones you've posted are merely backups (used for Last Known Good Configuration boots, and similar purposes)
REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\XiaobaiFs
REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\XiaobaiFs
REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs /S
Apologies, but here are the results from the command prompt:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
es\XiaobaiFs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\XiaobaiFs
Type REG_DWORD 0x2
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x1
Tag REG_DWORD 0x2
ImagePath REG_EXPAND_SZ system32\DRIVERS\XiaobaiFsForXp.sys
DisplayName REG_SZ XiaobaiFs
Group REG_SZ FSFilter Virtualization
DependOnService REG_MULTI_SZ FltMgr
WOW64 REG_DWORD 0x1
Description REG_SZ UNNOO Xiao Bai Redirector-filter driver (for xp)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\XiaobaiFs\Config
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\XiaobaiFs\Instances
C:\windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\servic
es\eventlog\System\XiaobaiFs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\XiaobaiFs
EventMessageFile REG_EXPAND_SZ %SystemRoot%\System32\drivers\XiaobaiFs
ForXp.sys
TypesSupported REG_DWORD 0x7
C:\windows\system32>REG QUERY HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X
iaobaiFs /S
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs
Type REG_DWORD 0x2
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x1
Tag REG_DWORD 0x2
ImagePath REG_EXPAND_SZ system32\DRIVERS\XiaobaiFsForXp.sys
DisplayName REG_SZ XiaobaiFs
Group REG_SZ FSFilter Virtualization
DependOnService REG_MULTI_SZ FltMgr
WOW64 REG_DWORD 0x1
Description REG_SZ UNNOO Xiao Bai Redirector-filter driver (for xp)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs\Config
ShadowRoot REG_SZ E:\Xiaobai\Shadow
Windows REG_SZ C:\windows
Users REG_SZ C:\Users
ProgramFiles REG_SZ C:\Program Files (x86)
ProgramData REG_SZ C:\ProgramData
Documents REG_SZ C:\Users\*\Documents
Desktop REG_SZ C:\Users\*\Desktop
Temp REG_SZ C:\Users\*\AppData\Local\Temp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs\Instances
DefaultInstance REG_SZ XiaobaiFs - Top Instance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\XiaobaiFs\Instances\XiaobaiFs -
Top Instance
Altitude REG_SZ 131700
Flags REG_DWORD 0x0
C:\windows\system32>
Phew! - I was worried there, for a minute!
We can delete those entries, I think - hopefully with no nasty consequences...
Please navigate to the following entries in Regedit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\XiaobaiFs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\System\XiaobaiFs
right-click on each, and select Export
Save the first as xbfs.reg
Save the second as xbfsevent.reg
Now right-click on each key, and select Delete
MAKE SURE that you've highlighted the correct Key before accepting the confirmation prompt - there is NO UNDO in the registry!
exit, and reboot.
Do you get any messages on boot?
wait 15 minutes, and reboot, then post the two event logs again.
Sorry Noel, I was away for a few days.
I did the reboot and there are no messages popping up.
Here are the event logs as requested. Thanks!