From a CD boot, select to enter the Recovery Console and use the commands:
chkdsk c: /R
No CD boot and no Recovery console, only blank screen and
blinking cursor. Anyway I downloaded an utility from the
driver manufacturer (self-booting diskette) and the disk
appears fine.
I also ran Windiag from Microsoft to test the memory,
it's fine.
Here, you can try (from MSCONFIG) selecting Diagnostic mode. This loads the
bare minimum necessities for windows to run on the next boot, even less
things run than when you select Selective startup. You can also let it boot
normally, not just to safe mode, when in diag mode (although, of course, a
great deal of things won't run because they haven't been
started properly).
Well, that's what I supposed. Let select the bare minimum
as you say and if it can boot into Safe Mode it will boot
into 'normal' mode as well.
Guess what?. The $=""?! won't boot into normal mode ,
even when I select "Diagnostic mode" or "Uncheck all" or
any combination of services/drivers. Man, it seems
*determined* not to boot.
Safe Boot must be doing something *else* to allow it to
boot, extra-hardware checks?. ACPI tricks?.
I might be wrong on this, but I don't think sfc is supposed to require RPC
related services. Perhaps you have an infection. But
after you boot normally
[..]
Really great explanation of services
but again the $%)
·$· is laughing at me, the RPC service is started, the
Locator RPC Services won't start because "it can't run in
Safe Mode". So it's a kind of Catch-22.
As whether sfc requires RCP I never ran it before but it
seems so. And again I can't start all the RPC services
under Safe Mode so I can't run SFC. Don't you love these
clever tricks? :-(
If sfc still will not run then I'd recommend removing the HDD from the
computer, setting its jumpers temporarily to make it be a slave drive (or
run it as a master drive on the secondary IDE channel), and check it for
virus on another computer that has up to date antivirus (maybe a repair shop
if you don't have access to another computer or to a friends). You might
need to do the sfc thing again once you put it back in your computer as a
master drive C.
That's one thing I probably will have to do, take the HDD
to another computer and chkdsk / sfc / viruscan it to
death. It will be a pain (specially if everything turns
out to be OK but still won't boot when returned) but it's
becoming the last option.
What are the last 3 lines in your c:\bootlog.txt file
after it has hung?
No bootlog.txt, I have a c:\windows\ntbtlog.txt that's
filling up pretty quick.
Last lines of this file follows (in Spanish) keep in mind
that this is an attempt of booting with almost every
service disabled and I'm not sure if the failed "normal
boots" really logs into this file.
"Controlador" means "Driver" and "cargado" means "loaded"
"No se ha cargado el controlador" means "Driver could not
be loaded"
No se ha cargado el controlador Controladores de audio
heredados
No se ha cargado el controlador Dispositivos para el
control de multimedia
No se ha cargado el controlador Dispositivos de captura
de vídeo heredados
No se ha cargado el controlador Códecs de vídeo
Controlador cargado \SystemRoot\System32\DRIVERS\tcpip.sys
Controlador cargado \SystemRoot\System32\DRIVERS\netbt.sys
Controlador cargado \SystemRoot\System32
\DRIVERS\netbios.sys
No se ha cargado el controlador Serial.SYS
No se ha cargado el controlador Processor.SYS
No se ha cargado el controlador AmdK7.SYS
No se ha cargado el controlador \SystemRoot\System32
\Drivers\PCIDump.SYS
Controlador cargado \SystemRoot\System32\DRIVERS\rdbss.sys
No se ha cargado el controlador PCLEPCI.SYS
Controlador cargado \SystemRoot\System32
\DRIVERS\mrxsmb.sys
No se ha cargado el controlador Fips.SYS
No se ha cargado el controlador Procesador AMD K7
No se ha cargado el controlador NVIDIA GeForce4 MX 440
No se ha cargado el controlador Puerto de comunicaciones
No se ha cargado el controlador Puerto de comunicaciones
No se ha cargado el controlador Puerto de impresora
No se ha cargado el controlador Puerto de juegos estándar
No se ha cargado el controlador Dispositivo MIDI
compatible con MPU-401
No se ha cargado el controlador C-Media AC97 Audio Device
No se ha cargado el controlador Creative EMU10K1 Audio
Processor (WDM)
No se ha cargado el controlador Creative Game Port
No se ha cargado el controlador Pinnacle WDM PCTV Video
Capture
No se ha cargado el controlador Pinnacle WDM PCTV Audio
Capture
No se ha cargado el controlador Pinnacle PCTV Data Service
No se ha cargado el controlador Códecs de audio
No se ha cargado el controlador Controladores de audio
heredados
No se ha cargado el controlador Dispositivos para el
control de multimedia
No se ha cargado el controlador Dispositivos de captura
de vídeo heredados
No se ha cargado el controlador Códecs de vídeo
Controlador cargado \SystemRoot\System32\Drivers\Cdfs.SYS
Controlador cargado \SystemRoot\System32\drivers\afd.sys
No se ha cargado el controlador \SystemRoot\System32
\drivers\afd.sys
No se ha cargado el controlador \SystemRoot\System32
\DRIVERS\rdbss.sys
No se ha cargado el controlador \SystemRoot\System32
\DRIVERS\mrxsmb.sys
Controlador cargado \SystemRoot\System32\DRIVERS\srv.sys
Controlador cargado \SystemRoot\System32
\Drivers\Fastfat.SYS
Uh, yes ... does "several patches" mean ALL security (critical) patches have
been applied that Microsoft offers? With today's
infections, it's imperative
I keep my computer pretty up-to-date, I can't say 100%
sure ALL patches because well they tend to come up rather
quickly.
Anyway, I don't have any public IP in my computer, it's
sitting behind a router that doesn't allow any incoming
connections so I'm quite safe (or that's what I thought)
I scan for virus regularly (updated patterns) and also
run from time to time both Ad-Aware and HijackThis to
keep things in place.
That was a long post, thanks for your suggestion and keep
it coming!