Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Desktop blank at Startup  (Read 17361 times)

0 Members and 1 Guest are viewing this topic.

Nicolaysen

    Topic Starter


    Rookie

    Desktop blank at Startup
    « on: March 03, 2010, 03:29:27 PM »
    I have followed all of the instructions in order and have posted the logs for Super Anti Spyware, Malware and Hijack This.  The only problem I encountered was when I was running the JavaRa to remove old versions of Java, it kept encountering a problem and had to shut down each time.  I appreciate any help that you can give me.

    [Saving space, attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Desktop blank at Startup
    « Reply #1 on: March 04, 2010, 08:40:49 AM »
    Hello Nicolaysen and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.
    ==================================

    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.


    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    =====================================
    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O18 - Filter hijack: text/html - {0FA7FD6B-47C3-425B-AE30-36383F1C4503} - (no file)


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.
    ======================================

    Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

    link # 1
    link #2

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts. (you will receive a UAC prompt, please allow it)

    Double-click combofix.exe and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix

    Windows 8 and Windows 10 dual boot with two SSD's

    Nicolaysen

      Topic Starter


      Rookie

      Re: Desktop blank at Startup
      « Reply #2 on: March 04, 2010, 03:24:21 PM »
      Here are my new Hijack This log and Combo Fix log.  Thank you for the help.

      [Saving space, attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Desktop blank at Startup
      « Reply #3 on: March 04, 2010, 04:53:03 PM »
      I noticed that you have this installed on your computer. Please read below about the dangers of Registry Cleaners.
      c:\program files\Registry Easy

      Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.

      There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry.

      For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

      Further reading: XP Fixes Myth #1: Registry Cleaners

      =========================================
      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]
      KillAll::

      File::
      c:\windows\Internet Logs\xDBA5.tmp
      c:\windows\Internet Logs\xDBA4.tmp
      c:\windows\Internet Logs\xDBA3.tmp
      c:\windows\Internet Logs\xDBA2.tmp
      c:\windows\Internet Logs\xDBA1.tmp
      c:\windows\Internet Logs\xDBA0.tmp
      c:\windows\Internet Logs\xDB9F.tmp
      c:\windows\Internet Logs\xDB9E.tmp
      c:\windows\Internet Logs\xDB9D.tmp
      c:\windows\Internet Logs\xDB9D.tmp
      c:\windows\Internet Logs\xDB9B.tmp
      c:\windows\Internet Logs\xDB9A.tmp
      c:\windows\Internet Logs\xDB99.tmp
      c:\windows\Internet Logs\xDB98.tmp
      c:\windows\Internet Logs\xDB97.tmp
      c:\windows\Internet Logs\xDB96.tmp
      c:\windows\Internet Logs\xDB95.tmp
      c:\windows\Internet Logs\xDB94.tmp
      c:\windows\Internet Logs\xDB93.tmp
      c:\windows\Internet Logs\xDB92.tmp
      c:\windows\Internet Logs\xDB91.tmp
      c:\windows\Internet Logs\xDB90.tmp
      c:\windows\Internet Logs\xDB8F.tmp
      c:\windows\Internet Logs\xDB8E.tmp
      c:\windows\Internet Logs\xDB8D.tmp
      c:\windows\Internet Logs\xDB8C.tmp
      c:\windows\Internet Logs\xDB8B.tmp
      c:\windows\Internet Logs\xDB8A.tmp
      c:\windows\Internet Logs\xDB89.tmp
      c:\windows\Internet Logs\xDB88.tmp
      c:\windows\Internet Logs\xDB87.tmp
      c:\windows\Internet Logs\xDB86.tmp
      c:\windows\Internet Logs\xDB85.tmp
      c:\windows\Internet Logs\xDB84.tmp
      c:\windows\Internet Logs\xDB83.tmp
      c:\windows\Internet Logs\xDB82.tmp
      c:\windows\Internet Logs\xDB81.tmp
      c:\windows\Internet Logs\xDB80.tmp
      c:\windows\Internet Logs\xDB7F.tmp
      c:\windows\Internet Logs\xDB7E.tmp
      c:\windows\Internet Logs\xDB7D.tmp
      c:\windows\Internet Logs\xDB7C.tmp
      c:\windows\Internet Logs\xDB7B.tmp
      c:\windows\Internet Logs\xDB7A.tmp
      c:\windows\Internet Logs\xDB79.tmp
      c:\windows\Internet Logs\xDB78.tmp
      c:\windows\Internet Logs\xDB77.tmp
      c:\windows\Internet Logs\xDB76.tmp
      c:\windows\Internet Logs\xDB75.tmp
      c:\windows\Internet Logs\xDB74.tmp
      c:\windows\Internet Logs\xDB73.tmp
      c:\windows\Internet Logs\xDB72.tmp
      c:\windows\Internet Logs\xDB71.tmp
      c:\windows\Internet Logs\xDB70.tmp
      c:\windows\Internet Logs\xDB6F.tmp
      c:\windows\Internet Logs\xDB6E.tmp
      c:\windows\Internet Logs\xDB6D.tmp
      c:\windows\Internet Logs\xDB6C.tmp
      c:\windows\Internet Logs\xDB6B.tmp
      c:\windows\Internet Logs\xDB6A.tmp
      c:\windows\Internet Logs\xDB69.tmp
      c:\windows\Internet Logs\xDB68.tmp
      c:\windows\Internet Logs\xDB67.tmp
      c:\windows\Internet Logs\xDB66.tmp
      c:\windows\Internet Logs\xDB65.tmp
      c:\windows\Internet Logs\xDB64.tmp
      c:\windows\Internet Logs\xDB63.tmp
      c:\windows\Internet Logs\xDB62.tmp
      c:\windows\Internet Logs\xDB61.tmp
      c:\windows\Internet Logs\xDB60.tmp
      c:\windows\Internet Logs\xDB5F.tmp

      Folder::
      c:\windows\SxsCaPendDel

      Registry::
      [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=-


      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
      ========================================

      ESET Online Scan

      Scan your computer with the ESET FREE Online Virus Scan

      * Click the ESET Online Scanner button.

      * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
      * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
      * Place a check mark next to YES, I accept the Terms of Use.

      * Click the Start button.
      * Accept any security warnings from your browser.
      * Leave the check mark next to Remove found threats and place a check next to Scan archives.
      * Click the Start button.
      * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
      * When the scan completes, click List of found threats.
      * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
      * Click the <<Back button then click Finish.

      In your next reply please include the ESET Online Scan Log

      Windows 8 and Windows 10 dual boot with two SSD's

      Nicolaysen

        Topic Starter


        Rookie

        Re: Desktop blank at Startup
        « Reply #4 on: March 05, 2010, 11:01:14 PM »
        Here are my new scans both Combo Fix and ESETScan.  Again, thank you for any and all help. 

        [Saving space, attachment deleted by admin]

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Desktop blank at Startup
        « Reply #5 on: March 06, 2010, 07:23:16 PM »
        Quote
        Again, thank you for any and all help.
        You're welcome.

        As you can see from the ESET scan, some of your infections came from that program. All the more reason for getting rid of it.
        How's your computer working now?


        Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

        Delete these files/folders, as follows:

        1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
        It must be Notepad, not Wordpad.
        2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

        Code: [Select]
        KillAll::

        File::
        c:\windows\Internet Logs\xDB9C.tmp
        c:\windows\Internet Logs\xDB5E.tmp
        c:\windows\Internet Logs\xDB5D.tmp
        c:\windows\Internet Logs\xDB5C.tmp
        c:\windows\Internet Logs\xDB5B.tmp
        c:\windows\Internet Logs\xDB5A.tmp
        c:\windows\Internet Logs\xDB59.tmp
        c:\windows\Internet Logs\xDB58.tmp
        c:\windows\Internet Logs\xDB57.tmp
        c:\windows\Internet Logs\xDB56.tmp
        c:\windows\Internet Logs\xDB55.tmp
        c:\windows\Internet Logs\xDB54.tmp
        c:\windows\Internet Logs\xDB53.tmp
        c:\windows\Internet Logs\xDB52.tmp
        c:\windows\Internet Logs\xDB51.tmp
        c:\windows\Internet Logs\xDB50.tmp
        c:\windows\Internet Logs\xDB4F.tmp
        c:\windows\Internet Logs\xDB4E.tmp
        c:\windows\Internet Logs\xDB4D.tmp
        c:\windows\Internet Logs\xDB4C.tmp
        c:\windows\Internet Logs\xDB4B.tmp
        c:\windows\Internet Logs\xDB4A.tmp
        c:\windows\Internet Logs\xDB49.tmp
        c:\windows\Internet Logs\xDB48.tmp
        c:\windows\Internet Logs\xDB47.tmp
        c:\windows\Internet Logs\xDB46.tmp
        c:\windows\Internet Logs\xDB45.tmp
        c:\windows\Internet Logs\xDB44.tmp
        c:\windows\Internet Logs\xDB43.tmp
        c:\windows\Internet Logs\xDB42.tmp
        c:\windows\Internet Logs\xDB41.tmp
        c:\windows\Internet Logs\xDB40.tmp
        c:\windows\Internet Logs\xDB3F.tmp
        c:\windows\Internet Logs\xDB3E.tmp
        c:\windows\Internet Logs\xDB3D.tmp
        c:\windows\Internet Logs\xDB3C.tmp
        c:\windows\Internet Logs\xDB3B.tmp
        c:\windows\system32\drivers\srv.sys
        c:\windows\Internet Logs\xDB3A.tmp
        c:\windows\Internet Logs\xDB39.tmp
        c:\windows\Internet Logs\xDB38.tmp
        c:\windows\Internet Logs\xDB37.tmp
        c:\windows\Internet Logs\xDB36.tmp
        c:\windows\Internet Logs\xDB35.tmp
        c:\windows\Internet Logs\xDB34.tmp
        c:\windows\Internet Logs\xDB33.tmp
        c:\windows\Internet Logs\xDB32.tmp
        c:\windows\Internet Logs\xDB31.tmp
        c:\windows\Internet Logs\xDB30.tmp
        c:\windows\Internet Logs\xDB2F.tmp
        c:\windows\Internet Logs\xDB2E.tmp
        c:\windows\Internet Logs\xDB2D.tmp
        c:\windows\Internet Logs\xDB2C.tmp
        c:\windows\Internet Logs\xDB2B.tmp
        c:\windows\Internet Logs\xDB2A.tmp
        c:\windows\Internet Logs\xDB29.tmp
        c:\windows\Internet Logs\xDB28.tmp
        c:\windows\Internet Logs\xDB27.tmp


        3. Go to the Notepad window and click Edit > Paste
        4. Then click File > Save
        5. Name the file CFScript.txt - Save the file to your Desktop
        6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



        ComboFix will begin to execute, just follow the prompts.

        After reboot (in case it asks to reboot), it will produce a log for you.
        Post that log (Combofix.txt) in your next reply.

        Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
        =====================================

        •Start HijackThis
        •Click on the Misc Tools button
        •Click on the Open Uninstall Manager button.
        •Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
        Copy and paste this file in your next reply.

        Windows 8 and Windows 10 dual boot with two SSD's

        Nicolaysen

          Topic Starter


          Rookie

          Re: Desktop blank at Startup
          « Reply #6 on: March 07, 2010, 12:46:39 AM »
          Dave,

          Here are the ComboFix file and the Hijack This Uninstall log.  The computer is running better, faster and smoother, but it is still blank at Startup for about 5-10 minutes then the icons show up.  I uninstalled the Registry Cleaner.  Should I uninstall the other programs that came with it.  Advanced Defrag, Driver Checker, Perfect Uninstaller. 

          Thanks again. 

          Chris

          [Saving space, attachment deleted by admin]

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Desktop blank at Startup
          « Reply #7 on: March 07, 2010, 01:17:15 PM »
          Quote
          The computer is running better, faster and smoother, but it is still blank at Startup for about 5-10 minutes then the icons show up.
          This is probably not related to malware.

          Quote
          Advanced Defrag, Driver Checker, Perfect Uninstaller. 
          You can keep them if you wish. The only one I was concerned about was the Registry tool.

          There are still a couple of programs that are questionable.

          Registry Mechanic 6.0 (Another program which alters the Registry. Your choice)
          Sonic Update Manager ( See this link .)

          There is something I want to talk over  with my mentor. I'll be back with some more news about this. 
          Windows 8 and Windows 10 dual boot with two SSD's

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Desktop blank at Startup
          « Reply #8 on: March 08, 2010, 05:04:16 PM »
          I was concerned with all those .tmp files in the ComboFix logs. As fast as we were deleting them, they were being created again. Could you please Update your ZoneAlarm and then adjust the ZoneAlarm logging so that it doesn't create anymore .tmp files. If not, it will eventually fill your HDD with .tmp files. They are not malicious; just takes up space on your HDD.
          Windows 8 and Windows 10 dual boot with two SSD's

          Nicolaysen

            Topic Starter


            Rookie

            Re: Desktop blank at Startup
            « Reply #9 on: March 08, 2010, 07:11:20 PM »
            Dave,

            Thank you for checking on all of this.  I have a couple of questions.  Do you want me to uninstall the Sonic Update Manger?  I will do it if you think I need to.  Next issue, I went to look for Zone Alarm and could not find it.  I know I have used it on my computer recently.  So I did a search, but it did not find a file that would work.  I downloaded a free version from CNET and went to run it.  Then the computer abruptly shut itself off.  When it came back on, it said that there was a blue screen issue.  I don't know what I am doing wrong.  Please help. 

            Chris

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Desktop blank at Startup
            « Reply #10 on: March 08, 2010, 08:04:58 PM »
            Quote
            Do you want me to uninstall the Sonic Update Manger?  I will do it if you think I need to.
            If it's not bothering you, leave it.

            You should see ZoneAlarm in your Start, Programs and also in the bottom right-hand of your screen. You disabled it just before you ran ComboFix.

            Quote
            When it came back on, it said that there was a blue screen issue.  I don't know what I am doing wrong.  Please help.
            What do you mean by a Blue screen issue? Are you able to boot your computer?
            Windows 8 and Windows 10 dual boot with two SSD's

            Nicolaysen

              Topic Starter


              Rookie

              Re: Desktop blank at Startup
              « Reply #11 on: March 09, 2010, 06:49:37 AM »
              I do not see Zone Alarm in either of those places anymore.  It is perplexing.  The blue screen shutdown was a shutdown to protect the computer.  That is what they said once it rebooted. 

              Chris

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Desktop blank at Startup
              « Reply #12 on: March 09, 2010, 11:27:35 AM »
              Quote
              do not see Zone Alarm in either of those places anymore
              Is it possible that you uninstall it? Let's run this tool.

              Download Security Check by screen317 from one of the following links and save it to your desktop.

              Link 1
              Link 2

              * Unzip SecurityCheck.zip and a folder named Security Check should appear.
              * Open the Security Check folder and double-click Security Check.bat
              * Follow the on-screen instructions inside of the black box.
              * A Notepad document should open automatically called checkup.txt
              * Post the contents of that document in your next reply.

              Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

              Quote
              The blue screen shutdown was a shutdown to protect the computer.  That is what they said once it rebooted. 
              Is your computer booting okay now? Have you had any more BSOD's (Blue Screen of Death)
              Windows 8 and Windows 10 dual boot with two SSD's

              Nicolaysen

                Topic Starter


                Rookie

                Re: Desktop blank at Startup
                « Reply #13 on: March 09, 2010, 01:53:13 PM »
                No more BSODs since I have not tried to run a new version of Zone Alarm. 

                I did the scan for you and it is attached.  It does show that I have Zone Alarm, but I don't how to access it and make it work and do the changes you asked. 

                Chris

                [Saving space, attachment deleted by admin]

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Desktop blank at Startup
                « Reply #14 on: March 09, 2010, 04:45:19 PM »
                Quote
                ComboFix 10-03-04.01 - Owner 03/04/2010  13:39:11.1.1 - x86
                FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
                The ComboFix log of Mar.04 shows a ZoneAlarm firewall.

                •Start HijackThis
                •Click on the Misc Tools button
                •Click on the Open Uninstall Manager button.
                •Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
                Copy and paste this file in your next reply.

                Please run ComboFix again and post the log here. I want to see if there are more tmp files in it.
                Next Post: Uninstall list and ComboFix log
                Windows 8 and Windows 10 dual boot with two SSD's