Win 7 black screen after logon

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheRealStig, Aug 21, 2013.

  1. TheRealStig

    TheRealStig Private E-2

    Hi,

    My computer suddenly only has a black screen after logon.
    I can run in safe mode OK.
    After realizing this, I ran Malwarebytes with attached problems found - I succesfully removed but problem persists the same way.

    The 5 logs per "Windows 7 Malware Removal/Cleaning Procedure" attached
    - please note that for Malwarebytes I've attached the first log only.
    I ran a second scan with no problems found.

    Thanks a lot in advance!

    Stig
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Quite a little bit to fix, so here comes the first part:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.
     
  3. TheRealStig

    TheRealStig Private E-2

    Dear Kestrel,

    Thanks a lot for promt help!
    Ran the requested fix apparently without problems.
    Please note I had to do so in SAFE MODE - the Windows Repair popped up a warning that it might not work correctly in SAFE MODE, but I didn't encounter any issues.
    Computer rebooted automatically and I'm now able to get started in normal mode, logging in and getting the desktop.
    I can't though launch neither Mozilla Firefox, Google Chrome nor the TASK MANAGER - the cursor just appear with the "waiting" symbol....
    It's not frozen (I can move the cursor around) but.....

    What next? :)

    Thanks a lot

    Stig
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. TheRealStig

    TheRealStig Private E-2

    Excellent.
    Please not that I (again) had to run in safe mode...
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Alot to do so here comes the first wave:

    Download BITS.reg to your desktop.


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BITS.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. TheRealStig

    TheRealStig Private E-2

    Thanks Kestrel,

    Had to run from SAFE MODE again...
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I can tell from the logs. No need to have to keep saying. :) Save you some trouble. Reviewing logs now.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download BFE.reg to your desktop. Do the same procedure for importing it to your registry as you did with BITS.reg, and also go through the same with BITS again too.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. TheRealStig

    TheRealStig Private E-2

    ok, all good ;)
    Imported both.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I just want to check for something.

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  12. TheRealStig

    TheRealStig Private E-2

    When I restart and tap F8 I do not get ADVANCED OPTIONS
    - I have to choose to boot from disk, DVD or USB?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Choose to boot from disk and let me know.
     
  14. TheRealStig

    TheRealStig Private E-2

    Just starts normally (though has become very slow) - no advanced option.
    Noted a message that I can hit DEL to enter SETUP menu?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what are you seeing now?

    (I am going to have to seek further advice from Chaslang regarding your machine. Alot is broken.)
     
  16. TheRealStig

    TheRealStig Private E-2

    OK. Got to the Windows logon, selected my user account, keyed in password.
    Got (parcially) the desktop screen but sort of only 10% appears.
    No icons, nowhere to click - though, not frozen, I can move cursor
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeking advice. Hang in there. :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does Task Manager open when you hit CTRL-SHIFT-ESC

    Also are you booting in just safe mode??? Try Safe Mode with Networking and get a new log from MGtools this way.
     
    Last edited: Aug 24, 2013
  19. TheRealStig

    TheRealStig Private E-2

    Thanks Kestrel, no problem!!
    Chaslang, tried to start in normal mode - got to the windows login, but after typing the password, nothing further happens.
    Can run in Safe Mode with Networking - log attached!
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, the logs look good. :) Can you describe what issues remain?

    Delete these:
    C:\Windows\Tasks\update-sys.job
    C:\Windows\Tasks\update-S-1-5-21-1338759378-2145454223-1684209335-1001.job
     
  21. TheRealStig

    TheRealStig Private E-2

    Good! Deleted the 2.
    When I 5min ago tried to start in normal mode, I got to the windows login - when typing password, nothing further happened. Nr by hitting ENTER nor neither by clicking with the mouse. I was not able to shut down either.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hopefully Chaslang will be able to further assist you, or you can post in the software forum regarding this.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my question from earlier on whether you can use CTRL-SHIFT-ESC to bring up Task Manager at this point.

    Back in message # 3 you said
    So this changed at some point???

    Thus far none of the logs have really shown any malware problems so you will likely have to take this to the Software Forum but try the below first.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     
    Last edited: Aug 27, 2013
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something else you may want to try before they disappear is using one of your System Restore points. Your logs showed two that could be of use:

    If these were from before your problem started, they could cure the issue....... assuming you get System Restore to work successfully.
     
  25. TheRealStig

    TheRealStig Private E-2

    Hi Chaslang,

    Tried staring normally - after keying in password I just get (some of) the blue windows screen (not the ERROR blue screen ;)).
    Ran SAFE MODE WITH NETWORKING and yes was able to start TASK MANAGER via CTRL+SHIFT-ESC.
    Then ran the scannow - counting up to 100% checked then just simply disappearing without any result prompted or anything.
    Chose to restart (automatically into normal mode) but still only get the blue screen after typing password.

    You're right - at #3 I was able to start in normal mode but the programs etc. did not work.
    At #16 I was no longer able to start normally - latest change was #9 BFE.reg. and BITS.reg - I didn't get to run FARBAR in #11 as Kestrel suggested....

    Finally tried to run both restore points - unfortunately the process stalls somewhere where the message is:
    "Please wait - System restore is initializing".

    Once again thanks a million for your help!

    Stig
     
  26. TheRealStig

    TheRealStig Private E-2

    Sorry, not bumbinp ;)
    Just tried once again and suddenly manage to run the RESTORE POINT from Aug 6.
    Win Update has run apparently without problems - I've also been able to update my internet browsers :cool
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so are your problems all solved now?

    Just an FYI: Every post bumps! ;)
     
  28. TheRealStig

    TheRealStig Private E-2

    hehe, understood!
    Looks like solved yes - any further test, scans or logs to run to ensure?
    :major
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. You were not having malware problems.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  30. TheRealStig

    TheRealStig Private E-2

    Excellent,

    If I had no malware, what did the found results from Malwarebyte 21/8 (attached) indicate?
    It appeared after downloading PrimoPDF from CNET site.....
    That's exactly the day trouble began :confused


    I don't find the MGclean.bat (assume because of restore) - can I just delete the MGtools folder?

    Once again thanks a lot!

    Stig
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is just adware/junkware stuff and MBAM already took care of it. It is not a major issue. PUP = Potentially Unwanted Program. Many people install PUP type programs on purpose and use them.


    No. System Restore would not remove the C:\MGtools folder. So if the folder is still there, and it should be, then MGclean.bat is there too. Perhaps you are only seeing MGclean without the .bat extension because you may have disabled viewing of file extensions now when you ran system restore.
     
  32. TheRealStig

    TheRealStig Private E-2

    Thanks for explanation reg. junkware!
    MGclean is (also) not found via search
    - if you're interested;), please find screendump of folder attached.
    If not, please consider it case closed!
    In any case, your help BERY MUCH appreciated!

    Stig
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well somehow you have managed to remove all of the utilities that are part of MGtools from that folder. You could just run the MGtools.exe program again which would put everything back in. You do not have to let it run thru to completion. Just run it and then once the black command prompt window opens, click on the X to close the command prompt. The files will already be extracted and you should see MGclean.bat. Run it as requested to do proper cleanup.
     
    Last edited: Sep 4, 2013

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds