Blue Scree Background

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Joedahobo, Aug 8, 2008.

  1. Joedahobo

    Joedahobo Private E-2

    When I start up my computer, my background is changed from the picture I used to have to just a plain blue screen. When I researched the blue screen on MajorGeeks.com, I found out that this is not necessarily a virus but it is almost a "joke" that can be pulled on anyone. It gave directions on how to give this blue screen to your friends, and when I searched the System32 folder in my computer, I found the executable file called ntoskrnl.exe, and I am wondering how I can get rid of it and get the blue screen to go away.

    Also, while the blue screen is on my computer, my computer will not allow me to change the background back to a picuture, or anything else for that matter. I need help please. And if it makes any difference, my computer runs off of Vista.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. Joedahobo

    Joedahobo Private E-2

    I have already done that. In the process of trying to remove all the spyware I had on my computer, I completed those processes to get rid of a program called Antivirus XP 2008. After that was removed, I began having this problem with the blue background. And I recently discovered that when searching through my files, none of the thumbnail pictures for both my pictures and file folders show up, although the files are still there and will still open. And whatever is going on is making it impossible for me to change my background on my computer from the blue background. I have attached the results from two of the scans that worked on my computer from the link that you gave me in the previous message as well.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you run malwareBytes and not have it fix everything it found?

    Could you not run ComboFix? Could you not run MGTools? I need those logs after you re-run MalwareBytes and fix everything.
     
  5. Joedahobo

    Joedahobo Private E-2

    I did have Malware Bytes remove everything it found the first time that I ran it.

    I ran Malware Bytes again today as both a quick scan and full scan. I will attach both logs.

    The next step in your process is to run ComboFix. The directions say that I first have to access the command prompt in the Windows Directory Recovery Environment. I have been following the directions from bleepingcomputer.com but so far have not been able to boot the computer using the Vista DVD or by using the F8 command during boot. I get a different screen with several options, none of which appears to be the one the directions is looking for.

    I get a black screen with the following options:

    Advanced Boot Options
    Choose Advanced Options for: Windows Vista (Use the Arrow Keys to highlight your choice.)

    Repair your computer

    Safe Mode
    Safe Mode with Networking
    Safe Mode with Command Prompt

    Enable Boot Logging
    Enable low-resolution video (640 x 480)
    Last Known good configuration (advanced)
    Directory Services Restore Mode
    Debugging Mode
    Disable Automatic Restart on System Failure
    Disable Driver Signature Enforcement

    Start Windows Normally

    Enter=choose Esc=cancel

    I have tried several of the obvious options but have not arrived at a point where it is obvious that I can access anything about the Windows recovery environment.

    I don't know what to do next to attempt to use the ComboFix tool, so I may try the MGT tools next.
     

    Attached Files:

  6. Joedahobo

    Joedahobo Private E-2

    Finished running MGTools and have attached log.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are stuck trying to install the Recovery Console using COmboFix, which is not really necessary to do ....it would require you to go into the bios and set the cd/dvd rom to first boot order...then boot into the cd.

    However.....you are mostly clean.

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Tell me what problems you are having.
     
  8. Joedahobo

    Joedahobo Private E-2

    I have "fixed" the three items in HJT as you suggested. After exiting, no change in the desktop background was noted. It was black. I right clicked on the desktop background and the left clicked on personalize. When I then left clicked on "Desktop Background", a window titled "Choose a Desktop Background" opens. This window has no thumbnails for any of the desktop background options EXCEPT solid colors. I have been able to change the desktop color to any color shown in the window. However, no thumbnails or their labels are visible in this window for any wallpapers or any pictures. If I move the cursor over the window, there is a light blue "ghost" thumbnail that shows up and the label is also displayed in a small window.

    However, If I click on "browse..." in the "Choose a Desktop Background" window, a window opens where I can see the saved pictures thumbnails and labels. When I select a saved picture, it does not show up in the "choose a desktop background" window and the desktop background does not change.

    If I click on Start and then click on pictures, the window that opens has a label for each thumbnail but no picture for any of thumbnails. When I click in the space above a thumbnail label where a thumbnail picture should be, the appropriate picture is displayed in a new window. If I right click on this picture and select "Set as Desktop Background," the desktop background does not change.

    The thumbnail pictures are also missing for games and videos as well.

    Could some necessary registry key have been deleted when CCleaner was run?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Interesting.......do this:

    Check your registry and tell me what the setting are for:
    HKEY_USERS\S-1-5-21-2996813556-57422227-942282164-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage

    HKEY_USERS\S-1-5-21-2996813556-57422227-942282164-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage
     
  10. Joedahobo

    Joedahobo Private E-2

    I need some assistance with this direction as I do not know how to check the registry nor determine the settingsfor the keys listed. Sorry - I am ignorant!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not real sure with Vista ...you should be able to go to run / type "regedit" without quotes ...when the registry opens ...expand each :HKey_Users / software / microsoft / windows / current policies / System \ NoDispScrSavPage ----what is the dword set at?

    Same for the other one.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think we should get a ComboFix log. Please just skip the part with the Recovery Environment and simply make sure the combofix.exe is on your Desktop. Then make sure that UAC is still disabled (if it is not, you need to disable and reboot first for it to take effect). Then double click the combofix icon to run it. Attach the log after it finishes.
     
  13. Joedahobo

    Joedahobo Private E-2

    I am not sure how to find what the dword is set at for both of those registry keys but when I finally got to where I found both listed it was in a window that had a column for data and both had 0x00000000 (0) in that column. I hope this is the information you were looking for.

    I ran ComboFix and the log is attached.
     

    Attached Files:

  14. Joedahobo

    Joedahobo Private E-2

    I was finally able to change my background back to one of my saved pictures and all the thumbnails show again in the folders. There is an odd file location that appears in the location menu when I try to change my background. C:/Windows/system32 shows as being a location. Should that be there or is it nothing to worry about?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay ....but I believe that you are seeing that your backgrounds are located in a file within the system 32 folder......are you having any other issues?
     
  16. Joedahobo

    Joedahobo Private E-2

    Nope that should be everything. Thank you very much for all your help. You guys rock
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...If you are not having any other malware problems, it is time to do our final steps:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds