Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
White screen while logging on to windows
#11
(01-14-2017, 06:33 PM)Partha Wrote:  
(01-14-2017, 06:05 PM)RECdevicehelper Wrote:  
(01-14-2017, 03:19 PM)GuiltySpark Wrote:  Those Dism commands don't work in Win 7.

As Compton suggests we need system diagnostics: https://www.belarc.com/free_download.html
Thanks for letting me know, forgot that it doesn't work with windows 7. I worked with too many Operating Systems! Big Grin
Well, to be precise, some of the dism commands do work but not that one
yeah I agree, depends on the OS Exclamation

#12
Okay, after a few days I am finally able to reply to this thread.
Apparently, I do not have the privilege to attach these files, so I had to host them elsewhere.

Here are the logs: SFC before, CheckHealth, ScanHealth, RestoreHealth, SFC after
And here is the Belarc Advisor Computer Profile report.

#13
Hi SmilerRyan,

There doesn't seem to be much wrong from the Belarc report, I would advise however, uninstalling iObit Advanced System Care (snake oil) it will do more harm than good.

Can you try creating a new user account and logging into that to see if the effects are the same.

#14
Okay, I have uninstalled Advanced Systemcare and restarted the PC.
The problem still occurs on my main account, but not on any others.

is they any chance this account could be freezing when it logs in?

#15
More than likely that particular account has been corrupted in some way, is the 3d screensaver disabled? if not try disabling and restart the computer.

#16
The screensaver is disabled, and is currently set to (None).
Here is the list of screensavers I have installed, if that is any help:


Attached Files
.jpg   bandicam 2017-01-15 13-07-28-321.jpg (Size: 75.37 KB / Downloads: 71)

#17
Ok if there is no working screensaver, then I would assume due to the working other accounts that this one is corrupted by either malware or a registry issue (probably caused by that snake oil).


Please download and run Adwcleaner post the scan logs.

Download and run EEK post the scan logs.

Download and run Farbar post the scan logs.

#18
Download Process Explorer from https://technet.microsoft.com/en-us/sysinternals/processexplorer.aspx, unzip the file and, run the exe with VirusTotal Support as in the video below





Just see if any of the ratings for the processes in the last column titled VirusTotal are in red. In the screenshot below, the ratings are in blue, indicating that no suspicious processes are active

   

If a process has a rating of 2/54 for instance, that would mean that out of 54 antimalware, 2 detects it as a threat

Such ratings will appear in red and not in blue. Let me know if any ratings in red appear

#19
I have downloaded the above 3 programs and run them.

Log files:
Adwcleaner
ESS
Farbar FRST / Addition

The chrome extension that was found was LivePage, which is an extension in the web store that i often use. I assume that was not the cause of the problem because i would actually have to open chrome for it to do this.

I checked the WhatsappAPI file and it seems like a rat that is no longer active. I deleted it and the folder from windows explorer.
Restarting after deleting the file did not make any different effect to the computer.

The only thing process explorer / virustotal detects is my screen recorder (bandicam) as 1/54. That seems fine to me.

#20
Please copy this to notepad and title Fixlist save it to the FRST folder.
Quote:Start
CreateRestorePoint:
CloseProcesses:
Emptytemp:
Task: {0B817291-51E0-4E80-80A7-6B7472B57AE2} - System32\Tasks\{30CD3AEB-7678-452A-BCA8-98A28FDC9D06} => pcalua.exe -a C:\Users\Ryan_2\AppData\Local\Temp\jre-8u73-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: {6146E38D-76B9-43BA-AF49-FD55CD204EA6} - \WPD\SqmUpload_S-1-5-21-2642175682-2510151592-2292122871-1010 -> No File <==== ATTENTION
Task: {A65649C2-4F61-4727-B94B-B35806501B3E} - \WPD\SqmUpload_S-1-5-21-2642175682-2510151592-2292122871-1001 -> No File <==== ATTENTION
Task: {C7695470-326D-4614-B176-37154194DA15} - \WPD\SqmUpload_S-1-5-21-2642175682-2510151592-2292122871-1006 -> No File <==== ATTENTION
Task: {FFCE9701-4899-4423-B3AD-2DECBDCD9302} - \WPD\SqmUpload_S-1-5-21-2642175682-2510151592-2292122871-1011 -> No File <==== ATTENTION
HKU\S-1-5-21-2642175682-2510151592-2292122871-1017\Software\Classes\exefile: <===== ATTENTION
HKU\S-1-5-21-2642175682-2510151592-2292122871-1017\Software\Classes\.exe: exefile => <===== ATTENTION
GroupPolicy: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
ACMD: ipconfig /flushdns
End
Open FRST and select Fix



Forum Jump:


Users browsing this thread:
2 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.