Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Policy Restrictions & Failed Windows 11 Boot. Possible rootkit?


  • Please log in to reply
26 replies to this topic

#16 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 02 March 2024 - 07:41 PM

I think it is possible this is the source of your system freezing. To test this, please disable virtualization.


Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

BC AdBot (Login to Remove)

 


#17 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted 02 March 2024 - 09:55 PM

I disabled virtualization, and then went into advanced startup settings to run the automatic repair again, but it still failed. This is the log file it spat out: 

 

Startup Repair diagnosis and repair log
---------------------------
Last successful boot time: ‎3/‎3/‎2024 2:47:07 AM (GMT)
Number of repair attempts: 1

Session details
---------------------------
System Disk = \Device\Harddisk0
Windows directory = C:\Windows
AutoChk Run = 0
Number of root causes = 1

Test Performed:
---------------------------
Name: Check for updates
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: System disk test
Result: Completed successfully. Error code = 0x0
Time taken = 15 ms

Test Performed:
---------------------------
Name: Disk failure diagnosis
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: Disk metadata test
Result: Completed successfully. Error code = 0x0
Time taken = 110 ms

Test Performed:
---------------------------
Name: Disk metadata test
Result: Completed successfully. Error code = 0x0
Time taken = 31 ms

Test Performed:
---------------------------
Name: Target OS test
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: Volume content check
Result: Completed successfully. Error code = 0x0
Time taken = 31 ms

Test Performed:
---------------------------
Name: Boot manager diagnosis
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: System boot log diagnosis
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: Event log diagnosis
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: Internal state check
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Test Performed:
---------------------------
Name: Check for installed LCU
Result: Completed successfully. Error code = 0x0
Time taken = 1922 ms

Test Performed:
---------------------------
Name: Check for installed driver updates
Result: Completed successfully. Error code = 0x0
Time taken = 500 ms

Test Performed:
---------------------------
Name: Check for pending package install
Result: Completed successfully. Error code = 0x0
Time taken = 1391 ms

Test Performed:
---------------------------
Name: Boot status test
Result: Completed successfully. Error code = 0x0
Time taken = 0 ms

Root cause found:
---------------------------
Boot status indicates that the OS booted successfully.

---------------------------
---------------------------



#18 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 02 March 2024 - 10:26 PM

I wouldn't expect Startup Repair to provide any clues. There were entries in the Event Viewer System report pointing to Virtualization potentially being the culprit. We just need to monitor things to see if your computer freezes.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#19 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted 03 March 2024 - 03:49 PM

I haven't had any freezes as of yet, but I'm having frequent graphics driver timeouts in which my screen will flash black, which is then followed by a drastic decrease in video resolution. These timeouts are generally triggered when I am watching a video on my device. I have already tried clearing the shader cache and updating my graphics drivers.

 

Thanks,

Isaac



#20 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted 03 March 2024 - 05:39 PM

Let's bypass NVIDIA and use the native windows video driver.

===================================================

Using VGA Driver in Normal Mode

--------------------
  • Click the Windows key + R at the same time
  • Type msconfig and hit Enter
  • Click the Boot tab
  • Place a check mark in Base video, then click OK
  • Restart your computer - Note: your screen resolution will change, that is normal.
  • Check your computer performance
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Results?

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#21 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted Yesterday, 02:22 PM

I tried changing to base video, but the video player issue with driver timeout persisted. If you would like, I could mark this thread resolved and contact AMD support, since we are now beyond any boot/malware issues. If you think you know how to resolve the issue, I'm also open to keep trying fixes.

 

Thanks!



#22 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted Yesterday, 07:41 PM

I updated my graphics drivers again to a release that came out a few days ago, and this seems to have fixed the issue. Thank you again for the help! Is everything resolved as long as I don't have any more graphics or boot issues?



#23 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted Yesterday, 09:31 PM

Yes, I think we are all set. Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#24 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted Today, 01:37 PM

The initial issues I had before factory resetting my computer included:

1. Laptop not booting until I disabled secure boot

2. Safe boot never functioning

3. FRST finding policy restrictions on Firefox and Edge

4. Windows Antivirus flickering off and on once

5. Windows Defender telling me that its settings were restricted and to contact my IT administrator for help (My laptop is a personal device)

 

Looking back, I am guessing that 4 and 5 were probably due to Malwarebytes or Avast One disabling Defender in favor of their software, which I had installed only to scan my device. I thought that there was a possibility of a rootkit because of the above symptoms, one which could hide from the superficial Malwarebytes and Avast One scans, which is what prompted my decision for a reset. In retrospect, how could I have determined if malware was the root cause of problems with my device, without waiting for the initial 3-5 day response time of this forum?



#25 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted Today, 02:31 PM

Greetings.

The issue with Virtualization (which you Disabled) was likely the cause for your booting issues and freezing. If you have experienced a repeat of that after we changed the setting let me know.

-----
 

FRST finding policy restrictions on Firefox and Edge

Typically these are not an issue unless there are browser specific symptoms. They can be easily reset if you'd like but if no symptoms appear or the settings seem irrelevant to the overall condition of the computer I ignore them.

-----

Multiple antivirus programs can cause abnormalities with Windows Defender. Even though Malwarebytes is designed to work in concert with Windows Defender, in order to have them both run (not turn off Windows Defender) a setting needs to be adjusted within Malwarebytes.

-----
 

how could I have determined if malware was the root cause of problems with my device, without waiting for the initial 3-5 day response time of this forum?

It doesn't usually take 3-5 days for a reply. In your case we replied within a day and a half. It is probably best to wait for a trained expert to look over your computer but it you wanted to pre-scan I would recommend Malwarebytes and ESET Online Scanner.

-----

One thing you originally listed as a concern was System Restore. In the newer versions of Windows Microsoft has decided to make the default setting Disabled.

Does this address everything?
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#26 Burritowel

Burritowel
  • Topic Starter

  •  Avatar image
  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted Today, 02:37 PM

Hi Gary,

 

I haven't had any further issues, so this does resolve everything. Thank you! Is there anything I should do for cleanup? Uninstall FRST?


Hi Gary,

 

I haven't had any further issues, so this does resolve everything. Thank you! Is there anything I should do for cleanup? Uninstall FRST?



#27 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,028 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:58 PM

Posted Today, 04:54 PM

Great thanks.

Here is our final step and some additional information to consider.

===================================================

KpRm by Kernel-panik

--------------
  • Download KpRm and save it to your Desktop (see here if you must use Chrome)
  • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
  • Right click on the icon and select Run as administrator
  • Click Yes on the Disclaimer
  • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
  • Click Run
  • Click OK on All operations are completed
  • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
  • You are free to remove any other tools/reports still remaining
===================================================

All Clean!

--------------

Your computer is now clean. Please consider this going forward.Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. ohmy_done.gif
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69




4 user(s) are reading this topic

0 members, 4 guests, 0 anonymous users