logo elektroda
logo elektroda
X
logo elektroda

Win 10 Log-in Issue: Black Screen after Logging In, Possible Virus/System Error, FRST64 Log

mallach 6030 7
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16633159
    mallach
    Level 10  
    Hello.
    Until the moment you log in, everything is in order. After entering the password, Welcome appears, followed by a black screen and nothing. Only ctrl + alt + del works. I do not know if it's a virus or a system error.
    I attach a log with FRST64, which I launched from the pendrive using the command line.
    Thank you in advance for your help.
  • ADVERTISEMENT
  • #2 16633323
    safbot1st
    Level 43  
    Still Addition.txt. I understand that you are doing logs from emergency mode
  • ADVERTISEMENT
  • #3 16633438
    mallach
    Level 10  
    safbot1st wrote:
    Still Addition.txt. I understand that you are doing logs from emergency mode

    Unfortunately, I can not enter emergency mode. It is exactly the same as with normal login.
    As I wrote in the first post, I started FRST64 from a pendrive after entering the command line that I can run from the diagnostic tools.
  • #4 16633496
    Kolobos
    IT specialist
    Did you replace any files?
    In the log you can see:
    C: \ Windows \ explorer.exe
    [2017-08-05 12:23] - [2017-07-23 15:12] - 004469840 _____ (Microsoft Corporation) FC1145751AC6E4FF1656381BB09A5AA3

    C: \ Windows \ SysWOW64 \ explorer.exe
    [2017-07-23 15:12] - [2017-07-23 15:12] - 004469840 _____ (Microsoft Corporation) FC1145751AC6E4FF1656381BB09A5AA3

    In normal mode, if you run the explorer from the task manager, does it start correctly or not?


    Execute Fixlist.txt for FRST:
    S4 ByteFenceService; C: \ Program Files \ ByteFence \ ByteFenceService.exe [145888 2017-04-19] (Byte Technologies LLC)
    S4 rtop; C: \ Program Files \ ByteFence \ rtop \ bin \ rtop_svc.exe [304456 2017-04-02] ()
    2017-07-23 15:11 - 2017-07-23 15:12 - 000002720 _____ C: \ Windows \ System32 \ Tasks \ {57CD816F-7A8A-DD63-74BA-5A4317F59EBC}
    2017-07-23 15:11 - 2017-07-23 15:11 - 000003360 _____ C: \ Windows \ System32 \ Tasks \ Opera scheduled Autoupdate 1464953812
    2017-07-23 15:11 - 2017-07-23 15:11 - 000002902 _____ C: \ Windows \ System32 \ Tasks \ Pawlik FilipWindbagsAntimonopolisticV2
    2017-07-23 15:11 - 2017-07-23 15:11 - 000002882 _____ C: \ Windows \ System32 \ Tasks \ Pawlik FilipGaloreApprobativeV2
    2017-07-23 15:11 - 2017-07-23 15:11 - 000002680 _____ C: \ Windows \ System32 \ Tasks \ ByteFence Scan
    2017-07-23 15:11 - 2017-07-23 15:11 - 000002586 _____ C: \ Windows \ System32 \ Tasks \ ByteFence
    2017-07-23 15:11 - 2017-07-23 15:11 - 000002288 _____ C: \ Windows \ System32 \ Tasks \ {0BE29FAC-5C6D-4ACC-803E-75FB9064484E}
    C: \ Windows \ Tasks \ {57CD816F-7A8A-DD63-74BA-5A4317F59EBC} .job
    C: \ Program Files \ ByteFence \
  • #5 16633604
    safbot1st
    Level 43  
    Here I also found something strange:
    2017-08-04 18:51 - 2017-08-04 18:51 - 000000214 _____ C: \ Windows \ Tasks \ CreateExplorerShellUnelevatedTask.job
  • ADVERTISEMENT
  • #6 16633612
    Kolobos
    IT specialist
    This file has no problem.
  • ADVERTISEMENT
  • #7 16634151
    mallach
    Level 10  
    Kolobos wrote:
    Did you replace any files?
    In the log you can see:
    C: \ Windows \ explorer.exe
    [2017-08-05 12:23] - [2017-07-23 15:12] - 004469840 _____ (Microsoft Corporation) FC1145751AC6E4FF1656381BB09A5AA3

    C: \ Windows \ SysWOW64 \ explorer.exe
    [2017-07-23 15:12] - [2017-07-23 15:12] - 004469840 _____ (Microsoft Corporation) FC1145751AC6E4FF1656381BB09A5AA3

    Yes, before FRST was running, I replaced the explorer from windows by taking it from the winsxs directory.
    After starting FRST, I replaced all files in the Bamital & volsnap section that were not verified. This time I took the files from another laptop with the same system. In addition to the substitution, I also removed this task:
    C: \ Windows \ Tasks \ {57CD816F-7A8A-DD63-74BA-5A4317F59EBC} .job
    After this change, the system did not log in, it only called the stop code 0xc000021a. I went back to the old winlogon.exe file and everything went back to its previous state.

    Kolobos wrote:

    In normal mode, if you run the explorer from the task manager, does it start correctly or not?

    After selecting the combination of Ctrl + Alt + Del keys and selecting the task manager, you have to wait about 15 minutes for the window to appear. An explorer is running in the processes. After completing the process and restarting after 30 minutes, a desktop appears, where I can right click on the empty space of the desktop, and when you hover over an icon or taskbar, the mouse cursor is still busy - the spinning circle.
    It looks as if something was blocking, but in the task manager the processor is practically zero and the memory usage is 15%.
    I am enclosing the log of the fixlist.txt implementation. Unfortunately, it's still the same.
  • #8 16634172
    arigato
    Level 28  
    Please forgive me, but literally a few posts (days) ago I wrote about something very similar, although here we are not dealing with BS.
    Please read the SMART disk (I assume it is a regular disk). You can use, for example, MHDD or Sentinel, Victoria (DOS). If it turns out that SMART shows "ZERO!" damaged sectors, please use MHDD and check at least a dozen or so percent of the disk area. Even ten. The test disc must be plugged in as "0"! After these operations perhaps SMART will wake up. This soft one, in spite of the lack of possible reallocation of damaged clusters, will show that there is a bad sector somewhere on the disk. Possible problems when starting up (power supply) or for example incorrect cooling (dusty laptop!) Can also be interpreted in conjunction with SMART values. Please paste all SMART values after scanning.
    We do not repair the disk !!!

Topic summary

The discussion revolves around a Windows 10 login issue where the user experiences a black screen after entering their password, with only Ctrl + Alt + Del functioning. The user suspects a virus or system error and has provided a log from FRST64 run from a pendrive. Responses indicate that the user cannot access emergency mode and has attempted to replace system files, including explorer.exe, leading to further complications. Suggestions include checking for damaged sectors using SMART diagnostics and tools like MHDD or Victoria, as well as verifying the integrity of system files and tasks. The user reports delays in task manager response and issues with desktop functionality after modifications.
Summary generated by the language model.
ADVERTISEMENT