PC starts up and goes black after Win Screen

Discussion in 'Malware Help (A Specialist Will Reply)' started by mjpeebles, Oct 16, 2008.

  1. mjpeebles

    mjpeebles Private E-2

    I'm able to boot into safe mode without issue. That's what I'm on right now.

    Spybot seems to remove problem, but it returns upon next reboot.

    I removed my nvidia driver and reinstalled a new one (from download). This seemed to help for most of today. Then my wife said the screen just went black in the middle of checking her email.

    Here are the symptoms: When I started the pc the other day, it ran through the bootstrap process. Just before completing this, the screen was covered with horizontal lines like this: | with text in front of them. Then the windows bootup starts. The background at this point has long diagonal green lines. It looks like an analog TV with bad reception. It looks like the desktop is going to come up and the screen goes black. The hard drive continues to run like it's starting up programs, but nothing else comes into view.

    I tried to find processes I didn't recognize and look them up online using a-squared hijack free. Everything I looked up was a standard windows process. I did find a mention that the NVidia driver can get infected and cause video issues. That's when I thought I'd try to remove it and put a clean driver on.

    I hope someone has some suggestions for me. The symptoms I'm experiencing are difficult to google for solutions.

    Here's my HJT log:

    Inline HJT log removed.
     
    Last edited by a moderator: Oct 16, 2008
  2. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello mjpeebles,

    This sounds more like a hardware/driver issue than it does a malware one. What problems was Spybot continually finding? Do you have a log saved from Spybot that you can post?
     
  3. mjpeebles

    mjpeebles Private E-2

    If it's a driver issue, why would putting the most current driver on the machine only fix the issue temporarily? If it's a hardware issue, why would putting on a new driver fix the issue at all?
     
  4. mjpeebles

    mjpeebles Private E-2

    I searched through Spybot to find a log file and couldn't find one. It appears spybot didn't retain a log file. I actually don't even see an option to create one. Next time I run a scan I'll attempt to save the results.
     
  5. mjpeebles

    mjpeebles Private E-2

    Okay, I removed the Nvidia driver in safe mode then rebooted the machine. Windows started in normal mode just fine. My screen is in VGA right now, but it is working.

    Here's a new log file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:17:24 PM, on 10/16/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    End of file - 7663 bytes
     
    Last edited by a moderator: Oct 25, 2008
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :)

    Rip_Chain removed you other "inline" hijackthis log earlier today, could you please give this a read through so you understand how to attach logs in the correct way.

    a guide on HOW TO: Attach Items To Your Post

    Thanks
    Kes13!
     
  7. mjpeebles

    mjpeebles Private E-2

    HJT Log is now uploaded...
    Matt
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    At no point does the Read and Run me outline that we need you to upload a HJT log :)

    Wait until Rip_Chain comes back to continue working thru the problems you are having. I see you were unable to locate a log from spybot search and destroy so just be patient and see what is suggested to you next :)
     
  9. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello mjpeebles,

    Those were simply ideas, the reason I mentioned them is because your log showed no signs of malware. Malware has been known to hide from HijackThis, though. Let's get some more information and make sure this isn't malware, if it isn't we'll run through some other diagnostic methods.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  10. mjpeebles

    mjpeebles Private E-2

    The problem was solved after going through the malware removal guide. Running Malware Bytes Antimalware identified a couple of registry issues. I've attached the log file. Hopefully, it helps the next person who has this issue.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is stronly recommended that you finish all of the READ & RUN ME and attach the other 3 logs that were requested. The infection you had has rootkit like behavior and also normally puts more files your PC than just the ones shown in your MBAM log.

    Files like below are frequently found and MBAM only found 2 of these:
     
  12. mjpeebles

    mjpeebles Private E-2

    Here are the other 3 logs. I have not toggled my restore point. I did install the Recovery Console that ComboFix requires. I did not encounter any critical errors since running ComboFix and have not rebooted my machine since running it.
     

    Attached Files:

  13. mjpeebles

    mjpeebles Private E-2

    Problem returned as you predicted. Occured after windows update autoran overnight. Computer rebooted to black windows screen.
    I booted into safe mode. Ran system restore to 2 days prior. Did not resolve the problem.
    Booted back into safe mode. Removed NVidia driver.
    Rebooted and started normal windows.
    Ran Scans again to get new logs to post: CCleaner (0 results), Super Antispyware (0 problems found), Spybot (0 problems found), Malware Bytes (0 problems)
    -Combofix receiving an error when trying to run this program again. "Were you trying to run CFScript? The name, CFScript appears to be incorrectly spelt". When I click okay the program terminates. I know "spelt" is not a word, so this is clearly suspicious.
    I Downloaded a fresh copy of Combofix and reran it, but received the same error.
    I checked the website bleepingcomputer.com to see if it addresses the error, but it does not.
    I'm not sure what to do next. I could try running MBtools, but would prefer to have explicit instruction to do so first.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It all depends on whether you are still having malware problems. The last logs you posted were all clean. You did forget to disable Spybot's Teatimer as we requested but there were no signs of malware in these last logs.
     
  15. mjpeebles

    mjpeebles Private E-2

    Did you read my last post?
    Yes, I am still having problems. I can't use my Nvidia driver. Whenever I put it on the machine I have malware problems.
    Also, you didn't address the error I was having with combofix. Seems like something's wrong if it won't run.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I did but nothing in that post mentioned any malware problems. All your logs were clean.

    I'm sorry but how is this a malware problem. Where did you get your drivers from? Were they downloaded from a reputable site. The malware seen in your logs has nothing to do with Nvidia.

    Yes and Spybot's Teatimer could have easily gotten in the way of using it or some other non-malware issue may be getting in the way. You did have some Windows Updates and then you also did a system restore. After doing that, anything we installed is no longer truly installed if they were installed after the restore point date because you have returned to a point in time of the date of the restore point.

    I did not ask you to run ComboFix again anyway since your logs were clean and we did not need it anymore at that time. After doing the System Restore you may or may not have reinstalled the malware that was originally removed. You should reinstall Malwarebytes ( a new version is out anyway) and run a scan with it. If the tdssservers malware came back, MBAM will tell us.
     
    Last edited: Oct 26, 2008
  17. mjpeebles

    mjpeebles Private E-2

    I will rerun malware bytes, toggle the restore, then reinstall a freshly downloaded driver. I always get drivers directly from the manufacturer web site. I'll repost if issues return.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just let us know.

    But if you are not having any more malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. mjpeebles

    mjpeebles Private E-2

    Problem came back. I rebooted to safe mode and attached a copy of what the screen looks like if that helps.

    I removed the nvidia driver in safe mode and rebooted and everything works again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything. And it still does not sound like a malware problem.

    Okay so does this contradict the above?
     
  21. mjpeebles

    mjpeebles Private E-2

    The first time I was posting a word doc, but didn't see the notice that it wasn't an eligible file type. This picture I took when I booted to safe mode. Then I removed the video driver. I don't know if the checkerboard pattern in images is related to the black screen issue or not.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Word Docs are valid. The size may not be.

    Ok but what's the problem.

    I have to insist that you post in the Software Forum at this point since we do not appear to be working on anything related to malware. All I can make out of your messages is that when you install a version of your Nvidia drivers, you have a problem with displaying your Desktop.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds