Black screen in Lenovo notebook, servicing didn't help.

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Welcome to our Community
Wanting to join the rest of our members? Feel free to sign up today.
Sign up
Status
Not open for further replies.
This is it.

SecurityCheck by glax24 & Severnyj v.1.4.0.57 [24.01.24]
WebSite: www.safezone.cc
DateLog: 16.08.2024 11:30:54
Path starting: C:\Users\PC\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: PC
VersionXML: 12.49is-15.08.2024
___________________________________________________________________________

Windows 11(6.3.22631) (x64) Professional Release: 23H2 Lang: Polish(0415)
Installation date OS: 09.07.2023 15:16:45
LicenseStatus: Windows(R), Professional edition The machine is permanently activated.
Boot Mode: Normal
Default Browser:
SystemDrive: C: FS: [NTFS] Capacity: [237.4 Gb] Used: [119.2 Gb] Free: [118.2 Gb]
------------------------------- [ Windows ] -------------------------------
User Account Control enabled (Level 3)
Centrum zabezpieczeń (wscsvc) - The service is running
Rejestr zdalny (RemoteRegistry) - The service has stopped
Odnajdywanie SSDP (SSDPSRV) - The service is running
Usługi pulpitu zdalnego (TermService) - The service has stopped
Zdalne zarządzanie systemem Windows (WS-Management) (WinRM) - The service has stopped
---------------------------- [ Antivirus_WMI ] ----------------------------
Windows Defender (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Zapora Windows Defender (mpssvc) - The service is running
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Malwarebytes version 5.1.7.121 v.5.1.7.121
--------------------------- [ OtherUtilities ] ----------------------------
Środowisko uruchomieniowe Microsoft Edge WebView2 v.127.0.2651.98
OpenOffice 4.1.14 v.4.114.9811 Warning! Download Update
------------------------------- [ Backup ] --------------------------------
Microsoft OneDrive v.24.146.0721.0003
------------------------------- [ Imaging ] -------------------------------
GIMP 2.10.36 v.2.10.36 Warning! Download Update
-------------------------- [ IMAndCollaborate ] ---------------------------
Zoom v.5.9.7 (3931) Warning! Download Update
Telegram Desktop v.5.2.3 Warning! Download Update
-------------------------------- [ Media ] --------------------------------
VLC media player v.3.0.18 Warning! Download Update
--------------------------- [ AdobeProduction ] ---------------------------
Adobe Flash Player 10 ActiveX v.10.1.102.64 Warning! This software is no longer supported. Please uninstall it.
------------------------------- [ Browser ] -------------------------------
Mozilla Firefox (x64 pl) v.129.0.1
Opera Stable 112.0.5197.53 v.112.0.5197.53
Vivaldi v.6.8.3381.53
Google Chrome v.127.0.6533.120
Microsoft Edge v.127.0.2651.98
------------------ [ AntivirusFirewallProcessServices ] -------------------
Malwarebytes Service (MBAMService) - The service is running
C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.2.0.1314
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe v.4.18.24070.5
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe v.4.18.24070.5
Usługa Program antywirusowy Microsoft Defender (WinDefend) - The service is running
Usługa inspekcji sieci Programu antywirusowego Microsoft Defender (WdNisSvc) - The service is running
---------------------------- [ UnwantedApps ] -----------------------------
VdhCoApp 1.6.3 Warning! Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering.
Wondershare Helper Compact 2.6.0 v.2.6.0 Warning! Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering.
----------------------------- [ End of Log ] ------------------------------
 

Attachments

Take care update the items in red in the Security Check log.

Go here, and update any drivers that need to be updated.

Rerun FRST64 one last time after completing the above steps and post fresh logs. I will have one last fix with FRST for you when I get home from work. 👍
 
Can I move my files, such as photos, videos, etc. back from the external drive to my notebook right now or should I wait for the last fix?
 
That’s fine. I’ll just be removing a couple of redundant things. Just a bit of cleaning up after myself.

We should also look into disabling a couple items.

Download Autoruns and Autorunsc Unzip it to your desktop and then right click
Capture.PNG

Run as Admin.
After the scan is finished then click on File----Then click----Save
The default name will be autoruns.arn make sure to leave it this way.
Attach the file in your next reply.
If the file is too large, then use catbox.moe or Ufile.io and send the link in your next reply.



Is there any budget for you purchasing some more ram for this machine?

Running at 70 percent is causing service time out errors. Hopefully with this last fix from FRST and disabling a few things in autoruns, we can get you down to at least 50 percent.

About to get to work. So I’ll check back on this later...
 
That’s what the next Frst fix and autoruns will address. I believe the machine is falling flat, due to resource constriction.

I can’t check these logs at work. Will have to wait I’ll I get home.
 
Sure It will be after midnight in my country, but I'll do what will be neccessairy in the morning.

The screen went black and the strange, very loud sound started to get out from the notebook. I wonder if it is not going black because of the unscreved case, because it often does when I move the notebook.

I only managed to write it and screen went black again but without sound, as always.
 
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.

Code:
start::
CreateRestorePoint:
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [sesvc] => "C:\Users\PC\AppData\Roaming\360se6\Application\components\sesvc\sesvc.exe" /b:1 /c:1 (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2023-01-25]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\Codecs\TrayMenu.exe (Cole Williams Software Limited -> )
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814968 2024-08-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [sesvc] => "C:\Users\PC\AppData\Roaming\360se6\Application\components\sesvc\sesvc.exe" /b:1 /c:1 (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\127.0.6533.120\Installer\chrmstp.exe [2024-08-16] (Google LLC -> Google LLC)
FF Extension: (No Name) - C:\Program Files (x86)\Netscape\Navigator 9\extensions\netscape9migrator@flock.com [not found]
CHR DefaultSearchURL: Default -> hxxps://pl.search.yahoo.com/search?fr=mcafee_uninternational&type=E210PL91105G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
FirewallRules: [{4BC7B70C-B5E4-4D02-A891-8A469F7C1272}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{3456F3DD-E5F9-42D6-9451-72FC02201664}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe => No File
CMD: sc stop "HPAppHelperCap"
CMD: sc stop "HPDiagsCap"
CMD: sc stop "HPNetworkCap"
CMD: sc stop "HPPrintScanDoctorService"
CMD: sc stop "HPSysInfoCap"
CMD: sc config "HPAppHelperCap" start= demand
CMD: sc config "HPDiagsCap" start= demand
CMD: sc config "HPNetworkCap" start= demand
CMD: sc config "HPPrintScanDoctorService" start= demand
CMD: sc config "HPSysInfoCap" start= demand
CMD: schtasks /Change /TN "EOSv3 Scheduler onLogOn" /Disable
CMD: schtasks /Change /TN "EOSv3 Scheduler onTime" /Disable
CMD: schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineCore{FC025B8A-D6FB-4E89-BCCB-25BB2A544254}" /Disable
CMD: schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineUA{18DB2535-B78E-4B29-8D05-9BCC5C531F29}" /Disable
CMD: schtasks /Change /TN "Opera scheduled Autoupdate 1674325752" /Disable
CMD: schtasks /Change /TN "VivaldiUpdateCheck-8fec06750b6fc3d1" /Disable
CMD: schtasks /Change /TN "GoogleSystem" /Disable
CMD: schtasks /Change /TN "GoogleUpdater" /Disable
CMD: schtasks /Change /TN "GoogleUpdaterTaskSystem129.0.6651.0{6942D0C8-177C-4C6F-B4F8-DC70FA7AC664}" /Disable
CMD: schtasks /Change /TN "HP Support Assistant" /Disable
CMD: schtasks /Change /TN "Firefox Background Update S-1-5-21-2586770459-4169581623-2973125490-1001 308046B0AF4A39CB" /Disable
CMD: schtasks /Change /TN "Firefox Default Browser Agent 308046B0AF4A39CB"  /Disable
CMD: schtasks /Change /TN "WarrantyChecker_DeviceScan" /Disable
CMD: schtasks /Change /TN "HP Print Scan Doctor" /Disable
CMD: schtasks /Change /TN "BitLocker Encrypt All Drives" /Disable
CMD: schtasks /Change /TN "BitLocker MDM policy Refresh" /Disable
CMD: schtasks /Change /TN "GatherNetworkInfo" /Disable
CMD: schtasks /Change /TN "RemoteApp and Desktop Connections Update" /Disable
CMD: schtasks /Change /TN "RemoteAssistance" /Disable
CMD: schtasks /Change /TN "RemoteAssistanceTask" /Disable
CMD: schtasks /Change /TN "FamilySafetyMonitor" /Disable
CMD: schtasks /Change /TN "FamilySafetyRefreshTask" /Disable
CMD: schtasks /Change /TN "XblGameSave" /Disable
CMD: schtasks /Change /TN "XblGameSave\XblGameSaveTask" /Disable


StartBatch:
cd %SystemRoot%\System32
lodctr /R
cd %SystemRoot%\SysWOW64
lodctr /R
winmgmt.exe /resyncperf
net stop pla
net start pla
net stop winmgmt
net start winmgmt
EndBatch:
Reboot:
end::


Right click Autoruns and run as admin.
Uncheck the items marked in BLUE, then reboot the computer.

1723854919276.png

1723855026702.png

1723855109639.png

1723855159570.png
 
The screen went black and the strange, very loud sound started to get out from the notebook. I wonder if it is not going black because of the unscreved case, because it often does when I move the notebook.


How do you feel about opening the laptop?
What is the exact make and mode of the lenovo?
Windows Key and R at the same time, type or copy and paste msinfo32 then hit enter.
Click edit: >> Select All: >>> Control C at the same time to copy, paste it here....OR

Screen shot that for me and post it here.
Use the Snipping Tool.
 
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.

Code:
start::
CreateRestorePoint:
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [sesvc] => "C:\Users\PC\AppData\Roaming\360se6\Application\components\sesvc\sesvc.exe" /b:1 /c:1 (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk [2023-01-25]
ShortcutTarget: CodecPackTrayMenu.lnk -> C:\Windows\SysWOW64\Codecs\TrayMenu.exe (Cole Williams Software Limited -> )
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3814968 2024-08-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2586770459-4169581623-2973125490-1001\...\Run: [sesvc] => "C:\Users\PC\AppData\Roaming\360se6\Application\components\sesvc\sesvc.exe" /b:1 /c:1 (No File)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\127.0.6533.120\Installer\chrmstp.exe [2024-08-16] (Google LLC -> Google LLC)
FF Extension: (No Name) - C:\Program Files (x86)\Netscape\Navigator 9\extensions\netscape9migrator@flock.com [not found]
CHR DefaultSearchURL: Default -> hxxps://pl.search.yahoo.com/search?fr=mcafee_uninternational&type=E210PL91105G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
FirewallRules: [{4BC7B70C-B5E4-4D02-A891-8A469F7C1272}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{3456F3DD-E5F9-42D6-9451-72FC02201664}] => (Allow) C:\Users\PC\AppData\Roaming\Zoom\bin\airhost.exe => No File
CMD: sc stop "HPAppHelperCap"
CMD: sc stop "HPDiagsCap"
CMD: sc stop "HPNetworkCap"
CMD: sc stop "HPPrintScanDoctorService"
CMD: sc stop "HPSysInfoCap"
CMD: sc config "HPAppHelperCap" start= demand
CMD: sc config "HPDiagsCap" start= demand
CMD: sc config "HPNetworkCap" start= demand
CMD: sc config "HPPrintScanDoctorService" start= demand
CMD: sc config "HPSysInfoCap" start= demand
CMD: schtasks /Change /TN "EOSv3 Scheduler onLogOn" /Disable
CMD: schtasks /Change /TN "EOSv3 Scheduler onTime" /Disable
CMD: schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineCore{FC025B8A-D6FB-4E89-BCCB-25BB2A544254}" /Disable
CMD: schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineUA{18DB2535-B78E-4B29-8D05-9BCC5C531F29}" /Disable
CMD: schtasks /Change /TN "Opera scheduled Autoupdate 1674325752" /Disable
CMD: schtasks /Change /TN "VivaldiUpdateCheck-8fec06750b6fc3d1" /Disable
CMD: schtasks /Change /TN "GoogleSystem" /Disable
CMD: schtasks /Change /TN "GoogleUpdater" /Disable
CMD: schtasks /Change /TN "GoogleUpdaterTaskSystem129.0.6651.0{6942D0C8-177C-4C6F-B4F8-DC70FA7AC664}" /Disable
CMD: schtasks /Change /TN "HP Support Assistant" /Disable
CMD: schtasks /Change /TN "Firefox Background Update S-1-5-21-2586770459-4169581623-2973125490-1001 308046B0AF4A39CB" /Disable
CMD: schtasks /Change /TN "Firefox Default Browser Agent 308046B0AF4A39CB"  /Disable
CMD: schtasks /Change /TN "WarrantyChecker_DeviceScan" /Disable
CMD: schtasks /Change /TN "HP Print Scan Doctor" /Disable
CMD: schtasks /Change /TN "BitLocker Encrypt All Drives" /Disable
CMD: schtasks /Change /TN "BitLocker MDM policy Refresh" /Disable
CMD: schtasks /Change /TN "GatherNetworkInfo" /Disable
CMD: schtasks /Change /TN "RemoteApp and Desktop Connections Update" /Disable
CMD: schtasks /Change /TN "RemoteAssistance" /Disable
CMD: schtasks /Change /TN "RemoteAssistanceTask" /Disable
CMD: schtasks /Change /TN "FamilySafetyMonitor" /Disable
CMD: schtasks /Change /TN "FamilySafetyRefreshTask" /Disable
CMD: schtasks /Change /TN "XblGameSave" /Disable
CMD: schtasks /Change /TN "XblGameSave\XblGameSaveTask" /Disable

startpowershell:
Set-Service AxInstSV -StartupType Disabled
Set-Service tzautoupdate -StartupType Disabled
Set-Service bthserv -StartupType Disabled
Set-Service dmwappushservice -StartupType Disabled
Set-Service MapsBroker -StartupType Disabled
Set-Service lfsvc -StartupType Disabled
Set-Service SharedAccess -StartupType Disabled
Set-Service lltdsvc -StartupType Disabled
Set-Service AppVClient -StartupType Disabled
Set-Service NetTcpPortSharing -StartupType Disabled
Set-Service CscService -StartupType Disabled
Set-Service PhoneSvc -StartupType Disabled
Set-Service PrintNotify -StartupType Disabled
Set-Service QWAVE -StartupType Disabled
Set-Service RmSvc -StartupType Disabled
Set-Service RemoteAccess -StartupType Disabled
Set-Service SensorDataService -StartupType Disabled
Set-Service SensrSvc -StartupType Disabled
Set-Service SensorService -StartupType Disabled
Set-Service ShellHWDetection -StartupType Disabled
Set-Service SCardSvr -StartupType Disabled
Set-Service ScDeviceEnum -StartupType Disabled
Set-Service SSDPSRV -StartupType Disabled
Set-Service WiaRpc -StartupType Disabled
Set-Service TabletInputService -StartupType Disabled
Set-Service upnphost -StartupType Disabled
Set-Service UserDataSvc -StartupType Disabled
Set-Service UevAgentService -StartupType Disabled
Set-Service WalletService -StartupType Disabled
Set-Service FrameServer -StartupType Disabled
Set-Service stisvc -StartupType Disabled
Set-Service wisvc -StartupType Disabled
Set-Service icssvc -StartupType Disabled
Set-Service WSearch -StartupType Disabled
Set-Service XblAuthManager -StartupType Disabled
Set-Service XblGameSave -StartupType Disabled
Set-Service SEMgrSvc -StartupType Disabled
Set-Service DiagTrack -StartupType Disabled
EndPowerShell:

StartBatch:
cd %SystemRoot%\System32
lodctr /R
cd %SystemRoot%\SysWOW64
lodctr /R
winmgmt.exe /resyncperf
net stop pla
net start pla
net stop winmgmt
net start winmgmt
EndBatch:
Reboot:
end::


Right click Autoruns and run as admin.
Uncheck the items marked in BLUE, then reboot the computer.

View attachment 14166

View attachment 14167

View attachment 14168

View attachment 14169

After doing this and rebooting, cursor is not visible and I can't unse notebook, how to fix that?
 
I understood you wrong ad I disabled everything that was checked in Autoruns. It all was marked with blue lines and I thought that I should disable everything. How to fix that? I am sorry!!!
 
Where is autoruns on your computer? On the desktop?

Since your mouse is disabled.
Hit the windows key and R at the same time.
shutdown /r /o
Hit enter.
This will boot you in recovery console.
There you can find safe mode, run Autoruns again and check mark everything listed, reboot.


Use Shift+Restart
Press the Windows logo key + X on the keyboard.
Hold the Shift key while clicking Restart from the Shut down or sign out menu.
Select Troubleshoot > Advanced options > Startup Settings >Restart.
After the PC restarts, there is a list of options. Select 4 or F4 or Fn+F4 (following the on-screen instructions) to start the PC in Safe Mode. Or in order to use the Internet, select 5 or F5 or Fn+F5 for Safe Mode with Networking.
 
Last edited:
Ok, I edited my last post, you need to get into safe mode then run autoruns, check everything then reboot the machine
 
Have to do a manual restart.
Use Method 5 here.
Then open Autoruns and check everything listed.
Reboot back into normal mode.
 
I have to go to work, you will have to re enable the items you unchecked in autoruns.
 
Or if you have a wired mouse. You disable your mouse pad with autoruns.
 
Status
Not open for further replies.