Windows 7 boot problems

Hi

I have windows 7 installed on a pc and it has trouble booting. When doing a normal boot it goes in repair mode.

When trying to boot into safe mode it goes up to the file awrvrt and then also goes into repair mode.

I tried chkdsk /r it gave a few errors at first but now returns zero errors.

I tried sfc /scannow but no help either.

I googled the fault and and landed here where i tried a few things but to no avail.

Could you please assist as there is pretty vital information on the drive. I have made a backup of the entire drive but would like to save it if possible.

Any help will be greatly appreciated

I am not sure if it is 32 or 64 bit version of windows 7

Thanks!

I found this thread https://forum.avast.com/index.php?topic=173730.0

I did the same steps as there using the first fixlist.txt and then the second.

Whit no change the pc boots and then goes into startup repair

When booring in safe mode it now loads up to file classpnp.sys before going into startup repair

Adding here FRST scan file.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-07-2015
Ran by SYSTEM on MININT-O0O6JN2 on 18-07-2015 16:53:07
Running from F:
Platform: Windows 7 Home Premium (X86) OS Language: English (United States)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM.…\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [94208 2006-04-29] (Elaborate Bytes AG)
HKLM.…\Run: [IndexSearch] => C:\Program Files\Nuance\PaperPort\IndexSearch.exe [46952 2011-08-02] (Nuance Communications, Inc.)
HKLM.…\Run: [PaperPort PTD] => C:\Program Files\Nuance\PaperPort\pptd40nt.exe [30568 2011-08-02] (Nuance Communications, Inc.)
HKLM.…\Run: [PDFHook] => C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM.…\Run: [PDF5 Registry Controller] => C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM.…\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM.…\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM.…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM.…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-16] (Avast Software s.r.o.)
HKU\Piet Van Wyk.…\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
AppInit_DLLs: c:\progra~2\bitguard\271832~1.68{61d8b~1\bitguard.dll => c:\progra~2\bitguard\271832~1.68{61d8b~1\bitguard.dll File not found

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-13] (Malwarebytes Corporation)
S2 PDFProFiltSrvPP; C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.)
S2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-01] (TeamViewer GmbH)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-05-09] (AVAST Software)
S3 Atc002; C:\Windows\System32\DRIVERS\l260x86.sys [29184 2009-07-13] (Atheros Communications, Inc.)
S1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [25160 2007-08-07] (Elaborate Bytes AG)
S3 ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [11984 2007-02-15] (Elaborate Bytes AG)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-13] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-13] (Malwarebytes Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-18 16:43 - 2015-07-18 16:53 - 00000000 ____D C:\FRST
2015-07-18 16:43 - 2015-07-18 16:43 - 00000000 ____D C:\Windows\System32\config\HiveBackup
2015-07-14 21:15 - 2015-07-14 21:15 - 00000000 ____D C:\Windows\System32\config\MYBACKUP
2015-07-08 22:31 - 2015-07-08 22:31 - 00003416 ____N C:\bootsqm.dat

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-14 20:13 - 2015-06-13 03:15 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-14 20:13 - 2015-03-26 01:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-14 20:13 - 2014-01-27 01:11 - 00000000 ____D C:\ProgramData\MicroWorld
2015-07-14 20:13 - 2012-10-19 06:00 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-14 20:13 - 2012-10-19 02:34 - 00000000 ____D C:\Users\Piet Van Wyk\AppData\Local\Mozilla
2015-07-14 20:13 - 2012-10-19 02:34 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-14 20:13 - 2012-10-18 22:35 - 00000000 ____D C:\Program Files\TeamViewer
2015-07-14 20:13 - 2012-10-17 07:59 - 00000000 ____D C:\Users\Piet Van Wyk\AppData\Local\Microsoft Help
2015-07-14 20:13 - 2012-10-17 07:30 - 00000000 ____D C:\users\Piet Van Wyk
2015-07-14 20:13 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2015-07-14 20:13 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2015-07-14 20:12 - 2015-06-13 03:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-14 20:12 - 2014-01-27 01:10 - 00000000 ____D C:\Program Files\eScan
2015-07-14 20:12 - 2014-01-27 01:10 - 00000000 ____D C:\Program Files\Common Files\MicroWorld
2015-06-30 23:11 - 2012-12-18 03:05 - 00000000 ____D C:\Users\Piet Van Wyk\AppData\Roaming\Nuance

Some files in TEMP:

C:\Users\Piet Van Wyk\AppData\Local\Temp\avguidx.dll
C:\Users\Piet Van Wyk\AppData\Local\Temp\GenericWndApi.dll
C:\Users\Piet Van Wyk\AppData\Local\Temp\jacob-1.15-M4-x64.dll
C:\Users\Piet Van Wyk\AppData\Local\Temp\jacob-1.15-M4-x86.dll
C:\Users\Piet Van Wyk\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp\MachineIdCreator.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp\oi_{1B53840D-19DD-40A2-9FD7-E587597B595F}.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Piet Van Wyk\AppData\Local\Temp_is2A1E.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_is2EFB.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_is3072.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_is4172.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_is4B84.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_is83A.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_isB868.exe
C:\Users\Piet Van Wyk\AppData\Local\Temp_isD25B.exe

==================== Known DLLs (Whitelisted) ============

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points =========================

Restore point made on: 2015-01-30 02:05:07
Restore point made on: 2015-02-06 05:24:16
Restore point made on: 2015-02-13 14:00:15
Restore point made on: 2015-02-23 07:08:44
Restore point made on: 2015-03-02 14:00:11
Restore point made on: 2015-03-11 01:23:36
Restore point made on: 2015-03-18 14:23:31
Restore point made on: 2015-03-26 14:00:21
Restore point made on: 2015-04-03 14:00:16
Restore point made on: 2015-04-11 14:00:15
Restore point made on: 2015-04-16 06:17:14
Restore point made on: 2015-04-16 06:28:50
Restore point made on: 2015-04-24 05:01:34
Restore point made on: 2015-05-22 00:14:20
Restore point made on: 2015-06-11 23:24:01
Restore point made on: 2015-06-15 16:43:28
Restore point made on: 2015-06-15 16:50:42
Restore point made on: 2015-06-23 03:13:32
Restore point made on: 2015-06-23 18:48:27
Restore point made on: 2015-06-27 18:36:06
Restore point made on: 2015-07-01 17:05:07
Restore point made on: 2015-07-07 16:35:58

==================== Memory info ===========================

Percentage of memory in use: 22%
Total physical RAM: 2038.24 MB
Available physical RAM: 1587.73 MB
Total Virtual: 2038.24 MB
Available Virtual: 1585.36 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:403.46 GB) NTFS
Drive f: () (Removable) (Total:3.72 GB) (Free:3.68 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.04 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: CD6C06D7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 3.7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

LastRegBack: 2015-07-02 14:56

==================== End of log ============================

Please do not post logs, but attach them to a post.

Give this a try:

  1. Boot the computer to windows recovery mode.
  2. Click Commmad Prompt, type in:
    rename c:\windows\system32\drivers\classpnp.sys classpnp.old
  3. Try to boot in safe mode.
  4. If safe mode is working, try a normal boot.

Hi Eddy

Many thanks for your reply i change the classpnp.sys file to classpnp.old.

Now in safe mode it goes up to disk.sys then goes into startup recovery.

Busy googling that.

Thanks so much!

If anyone else has any suggestions i would really really appreciate it.

I can be wrong ofcourse, but I don’t believe disk.sys is the problem but (likely) a driver that is trying to load after disk.sys.
Did you recently changed hardware ?
Or took a card out for cleaning and put it back in again (or something like this) ?

No nothing this is a bog standard work pc it does not even have a gfx card. it has one stick of ram one hd and a dvd drive. Nothing has been changed in long time. When i load the first fixlist file that essexboy suggest it goes back to hanging on aswRvrt.sys. If i could just get back into windows safe mode i can uninstall avast.

Any ideas anyone?

It is not Avast it is windows itself that is broken https://social.technet.microsoft.com/Forums/windows/en-US/f6dd9572-395b-4e69-b12c-17324bd6a434/windows-7-freezes-on-disksys?forum=w7itprogeneral

I would just “get over and done with it” and perform a clean installation of windows.

Yeah tried a few things in that thread thanks. Gonna do a clean install and start over.

Thanks to everyone that helped appreciate it