Windows 7 boot fails on aswrvt.sys

Hi all,

Since this morning, the Windows boot is failing (the Welcome screen freezes or I’ve got a “memory blue screen”).

I’ve tried to restore, even an old one, but it does the same.
I’ve tried to run in safe mode, and it appears that the boot is stoping on aswrvt.sys.

I therefore load Farbar Recovery Tool and run a scan, and get the FRST.txt (attached, I don’t know if it could help).

Could you please save me ?

Thanks and kind regards
tihitibo

if you can’t boot the computer, how did you run a scan with FRST? wouldn’t the computer have to be booted before you could run any programs on it?

Hi,

I can’t run windows itself, I’ve just succeeded to access the DOS screen, choosing “Dos Prompt” with F8

Thanks,
tihitibo

Hi,

When I wrote “the boot fails”, I meant “the Welcome screen freezes or I’ve got a memory blue screen”.
So, I’ve used the prompt dos from F8 and run FBRT from a usb.

tihitibo

Hi there, there is no guarantee that this will work

Download the attached fixlist.txt to the same USB as FRST
Run FRST as before and press fix

On completion try a normal boot

Hi,
some services have been correctly removed.
And when I reboot, I directly went to the memory blue screen.
Do you wish to have a new scan log ?

Thanks,
Regards
Sylvain

Are you able to get to the safe mode menu ?
Does it have a repair my computer option ?
If so then select that and run the windows memory diagnostic

No, it doesn’t fix the issue.

When I try to boot (safe mode or normal), it’s still displaying (shortly) the startup windows screen and then displaying the blue screen flush memory.

thanks for the help,
tihitibo

Do you have the windows CD so that we can use the recovery console

Hi,
No, the laptop was just delivered with a “restore from factory” disk…
Regards
tihitibo

What version of windows are you running ?

And is it 64 or 32 bit

Hi,

Windows 7 Pro, 64 bit

tihitibo

Hi you will need an operating computer and a USB stick of at least 4Gb

Download the following two programmes to your desktop :

  1. Rufus

For 32bit systems
2. Windows Vista RC

For 64bit systems
2. Windows Vista RC

Insert the USB stick Then run Rufus

https://dl.dropbox.com/u/73555776/rufus.JPG

Select the ISO file on the desktop via the ISO icon.

Press Start Burn

https://dl.dropbox.com/u/73555776/RufusISO.JPG

Insert the USB into the sick computer and start the computer. First ensuring that the system is set to boot from USB
Note: If you are not sure how to do that follow the instructions Here

When you reboot you will see this.
Click repair my computer

https://dl.dropboxusercontent.com/u/73555776/W7%20repair.png

Select your operating system

Select System Restore

https://dl.dropboxusercontent.com/u/73555776/W7%20Command.png

Restore your computer to a few days ago

Hi,

thanks,
I’m at work today, I’ll test it tonight and tell you.
Thanks again,

tihitibo

tihitibo, i am sorry that you are having problems…

i think that you must have a malware-infection, probably a zeroaccess infection, that is preventing “aswrvt.sys” from running, causing the problem…

not being able to boot seems like a major problem… i don’t know if it is possible to resolve the problem, or not…

i just want to give you some advice so that it doesn’t happen again… some people might object to my saying this but i believe that having “java” installed is responsible for virtually all malware-infections… i also believe that it is important to use high security-settings with one’s browser… so, my advice is to not have “java” installed and to use the “firefox” browser along with the “noscript” and “adblock plus” addons…

if you are not familiar with using “noscript”, it might seem difficult, and complicated, at first, but it really isn’t difficult to figure things out with it, or to use it…

if you use “internet explorer”, you can adjust its security-settings, using high security-settings for all zones except the “trusted sites zone”, where the “medium” security-level would be used, however, using high security-settings with IE can be a little difficult… it is easier to use the “firefox” browser, along with the “noscript” and “adblock plus” addons…

using high security-settings in IE restricts “javascript”… for websites where you need for javascript to be able to run, add those to IE’s “trusted sites zone”, where javascript is allowed to run…

the problem is, most webpages use data that comes from multiple sources and, with IE, it is not easy to see what those sources are and, so, if you need to add those to the “trusted sites zone”, that is a problem… with “noscript”, you can see all of the sources of the data in the webpages, so it is easy to allow scripting for those, if needed, and all you have to do is click on it, in contrast to IE where you have to manually add the domains to IE’s “trusted sites zone”, if you first can manage to figure out what needs to be added to the “trusted sites zone”…

so, to prevent more malware-infections, in the future, do not have “java” installed and use the “firefox” browser, along with the “noscript” and “adblock plus” addons…

of course, another way to avoid the problem that you are having would be to not have “avast” installed…

i saw that your windows-account uses the name “developer”… i am not sure what developing you are involved in… it could be the development of software or it could be the development of real estate, or something else… the point is that i assume that you are a “professional” of some type and, so, you might need “java” for your work… some people need “java” for their work… if you have to have “java” installed, for one thing, keep it up-to-date… also, you might be able to use “java”, as needed, while still having it disabled in your browser, which probably would help to make your computer more secure… it is possible to have “java” installed while having it disabled from running in your browser:

http://www.google.com/search?complete=0&site=webhp&source=hp&q=disable+java&btnG=Search&gbv=1&sei=RrpVUsLdNY7e8ASx0ICADg

if i was having the problem that you are, where your computer won’t boot, i don’t know how i would resolve that, short of “reformatting”… if i knew more about computers, i would think that it would be possible to pull the harddrive, plug it into another computer, and, then, either modify it, either deleting files or changing their “permissions”, maybe making it to where it would work, or, at least, to save some files from it, if needed, before reformatting it…

i don’t like “reformatting”…it takes me a lot of time to restore my computer…but i am able to do it, when needed… i backup all of my files on a regular basis, so nothing is lost by “reformatting”… some people use “imaging” programs to backup their whole computer, which is a good idea, i am just not familiar with doing that…

Hi REdWolf,

Thanks for the advices. Indeed, the laptop is used for IT developpement, and may need Java.
I’m not able to work on it until next Monday, but I’ll try the Rufus track (I have another laptop nearly the same than the one that crashes, so I hope I could create a repair from it).
We’re using firefox and “addblock”. I suspect the user of the laptop to do not have reboot for a long time… and therefore, some of the security updates (windows, avast) have probably not been set at time.

I update the thread on Monday, to tell if the Rufus method has worked. Otherwise… I’ll copy the critical data using the DOS to an usb (10 minutes of work ;)) and reformat the laptop.
Thanks again,
tihitibo

Hi all,

bad news about th “Win 7 RE” iso :
DUE TO COPYRIGHT INFRINGREMENT NOTICE ALL LINKS TO SPECIFIC RE ENVIROMENTS HAVE BEEN REMOVED EVEN KNOW THEY WHERE JUST REDIRECTS TO THE SOFTWARE MANUFACTURERS OWN DOWNLOAD

I search a link, but it seems I’ll hardly find it.

Regards
tihitibo

Hi,

got it !
Not easy, I give my steps, not sure they were all necessary :

  1. Create a disk recovery from another machine using the same windows version
  2. Boot on with the infected laptop, and repair
  3. When rebooting again, it failed another time. So, I access to the dos prompt and run Diskpart (don’t ask me why I had this idea…)
  4. The Windows volume, normally on C, was shift on D, and the partition was not “active” anymore. I reassign the letter and reactivate the partition as active.
  5. Then reboot and it worked ! I’ve quicky ran adwcleaner that does some housekeeping, and everything seems now ok.

Thanks for your big help,
tihitibo

Hi again,

last help required : I don’t know how to close the thread… can you help me a last time ?
Thks,
tihitibo