I used CCleaner to clean the registry, made a back-up, rebooted to black screen, restored the registry backup, still broken.

bobbyboulders

Honorable
Oct 10, 2013
17
0
10,510
Things i've tried:

System restore
Startup repair
Booting in safe mode
Rebooting multiple times

I have windows installed twice on my machine, such that prior to booting windows I'm asked to log onto

1. Windows 7
2. Windows 7 (recovered)

I used my Windows 7 recovered to access the registry backup and restored it from there.

I have Windows 7 Ultimate 64bit.

I would value anyone's help.
 
Solution
I would get into windows (however you can) backup critical data to cd or external device, then erase and reformat your hard drive, then do a fresh install of win 7. Good Luck.


Hi bigkid thanks for the prompt response.

Sorry, to clarify:
I used CCleaner's registry clean function because I thought it might help resolve a slow computer. I have since discovered that there is no need for this/it is useless.

I backed up the registry (clicked "yes" to back up)

The next time i started up my computer (logging into 1. Windows 7 above) i got the windows loading screen but then afterwards just a black/blank screen with the white cursor.
So, I then rebooted into an alternate identical windows 7 64 bit (2. Windows 7 ((recovered)) above) that was my original windows, which I had to reinstall after the original windows (2.) I had corrupted(?) which was fixed - I've been using it this way (logging into 1.) for at least 2 years with no issues.
Once inside this windows (2.), I went to the registry back up file from CCleaner (D:/Users/MyDocuments [sic]), double clicked to restore it, got the message pop up that it had restored all registry files successfully and rebooted to the 1. windows but still got the black screen.

Then I started with F8, tried rolling back to a system restore before I'd done the CCleaner - no change
I tried startup repair - no change (infact, it detected no problems)
I've tried booting into safe mode - black screen (no change)
I've tried rebooting normally multiple (10+) times

I've also now just tried memory repair mechanic - no change.

If you need any more info please ask.

Thank you
 
I would get into windows (however you can) backup critical data to cd or external device, then erase and reformat your hard drive, then do a fresh install of win 7. Good Luck.
 
Solution




I was afraid you'd say that. Is there no other way?
 
you most likely picked up a virus -- but with reg cleaner and rollbacks and such you might have fouled up the registry, you'd be best off doing a fresh install - but - if you want to try --- scan your system for viruses, you can use something like malware bytes, its free and can get rid of some crap....also Kaspersky's website offers a free 'rootkit' virus killer - rootkit viruses can hide from some scanners.
pcpitstop.com is a great site for scanning the health of your system - and the scans are free...but remember even if it says you don't have a virus you may still have a rootkit virus.

here's a link to the rootkit virus utility: http://support.kaspersky.com/us/5350

 


Hi bigkid

Thank you kindly for the advice (I've been away for a few days). I'll try the rootkit killer and post the progress.

...

Ok, I scanned with Malwarebytes and got 7 "problems" one of which is registry. I can't see if I can attach anything to this post (I have a screenshot) so here's the log:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.13.02

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
XXX :: XXX [administrator]

13/10/2013 11:53:37
mbam-log-2013-10-13 (11-53-37).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 202955
Time elapsed: 6 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoSMHelp (PUM.Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.


Folders Detected: 1
C:\Users\XXX\AppData\Local\Temp\ct2504091 (PUP.Optional.Conduit.A) -> No action taken.

Files Detected: 5
C:\Users\XXX\AppData\Local\Temp\ct2504091\ism.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\XXX\Downloads\DAEMONToolsPro500316-0317.exe (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\XXX\Downloads\DTLite4453-0297(1).exe (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\XXX\Downloads\DTLite4453-0297.exe (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\XXX\Local Settings\Temporary Internet Files\Content.IE5\UD7YS831\ism[2].exe (PUP.Optional.Conduit.A) -> No action taken.

(end)

I'll try the rootkit now and report back

...

Just ran the rootkit - 5 threats detected (after changing the parameters, the first scan found nothing) I don't know if a log will be created so here it is typed out:

(All unsigned file, All Suspicious object medium risk)
1. Service: CTAudSvcService
2. Service: hpqcxs08
3. Service: hpqddsvc
4. Service: Net Driver HPZ12
5. Service: PassThru Service

The only really interesting one is 4. as it's in Windows folder and is system32 and the rest are Creative (1.) HewlettPackard printer (2. 3.) or HutchinsonTeleCom mobile phone (5.):

C:\Windows\system32\HPZinw12.dll

I've quarantined them all anyway. Now to reboot.
 


Hi bigkid

No, doesn't seem to have solved it. Although the use of those two programs has helped identify some issues I guess, so many thanks for the advice.

I've just started to backup all the files I want to keep to reinstall and I'll then format the partition.

Things I learned:
Never use any "registry fixer" again!
Download Kaspersky and bin AVG and Avast.
Use Malwarebytes everyday.

...
Thanks for the info on 4. - The printer software with HP was such a pain in the derriere, so many unneccessary programs.
...

Actually, one thing I haven't tried yet is to repair with the windows disk. Is it worth it? - By that I mean, will it rewrite the registry values I have deleted/damaged?

...

I'm trying to format the partition with the 1. Windows on (that I want to reinstall) and I'm getting an error message saying Windows was unable to format the partition. I;ve got full admin control over it and can't seem to find an answer online. What would the reason be for windows not allowing me to format the partititon?
 


Thanks bigkid, I'll try it and get back to you
It's a whole HDD. I've got 2, 1 that is partitioned with the 2. Windows on and then this is a different disk actually come to think of it.
...
Nah it's cool, I've got a 1TB USB HDD that I've put all the files I want to keep on.
Windows 1. (the blacked out one now) is on a non partitioned HDD. The Windows 2 is on a partitioned HDD.
...
Man I wanna pull my teeth out.
The cmd is saying:
"Clean is not allowed on the disk containing the current boot, system, pagefile, crashdump or hibernation volume.

Is this because I'm running it from windows? I've selected the right HDD.
 


No no, the drive I'm trying to clobber is the one with the windows on that black screens on start up. The windows I'm using right now is on a different drive, different hard disk altogether.
It gets better - now the black screen windows drive has disappeared, as has the rest of the partition that isnt the windows partition.
So: Windows 7 (recovered) is on C partition of HDD 1, the rest of the partition is named Z
The black screen windows is on drive D: not partitioned HDD 2.
In terms of disk names in diskpart, C and Z are on disk 0 and D is on disk 1
...
I've tried doing diskpart in command prompt from safe mode on startup but i'm getting the same error message
 


I worked out why Z had disappeared, the drive letter became removed from Z to *, the D drive is also * but I cant reassign a drive letter, but as you said more later.

I'll reinstall now (or attempt to), it's just I'd quite like to install the new windows onto the other hard drive and partition it (the D drive). I'll install onto the C drive by creating a new partition if it lets me.
 


I've tried reinstalling windows and it didn't work, I got an error message 0x80070003 - I've got a message at start up now saying bootmgr (boot manager) is missing. Press Ctrl+Alt+Del to restart.
...
Don't suppose you have a guide to "restore factory settings to your computer"?!
...
I repaired with the windows disk, I'll try wiping the HDD now
 
Dear Lord!

I don't know what did it but I thought I'd just try and format the D: drive (which reappeared) and it's formatted no probs.

Going to try and install onto D: now - although I'm concerned I'll receive the same error message. Here goes...
 
disconnect that other drive !!!!!!!!!!! I have to step away for a few hours --- if you get win installed please don't connect the other hard drive yet - just get things going with the
newly formatted drive
 


I'm into the install now so can't disconnect it. What's good is that there's no error message so far and it's gone past the 17% complete that it had before. 60% and counting...
...
It's all over! Clean install up and running and working. I'm not sure which post of yours to mark as the solution, probably the first one! But also the one on wiping the hard drive, something obviously worked.
Can't thank you enough. Is there anything I can do to say thanks? Promote your own website or something?
 
yes -- enable ahci that way. It's debatable, but it's a more efficient way for the disk to seek data and It gives you the ability to connect
drives while the system is up - it's called hot swapping. In the future, if you get an ssd, they run faster with ahci enabled.
after you boot up to windows you can then connect your second drive to access that data. you may be able to delete out just
the win install on that drive - however you do , get rid of it. you said you wanted win install on the 2nd drive - best way would be to
go through what you did to clear the first drive and do another fresh install - if you do this, once done, re-init the first to remove that win install.
good luck, I'd appreciate it if you 'pick as the solution' for me.
 


Thanks bigkid - really appreciate all your help and advice.