FBI virus and black screen with cursor.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DigitalWarlord, Sep 3, 2013.

  1. DigitalWarlord

    DigitalWarlord Private E-2

    A friend of mine told me she had the FBI virus. I figured I could fix it no problem with a few scan. Fast forward to her giving me her laptop. I turned it on and after logging into to the only it just loads a black screen and cursor. This happens in safe mode as well. I'm not sure how to go about fixing this thing. Any and all help would be appreciated.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What operating system is this please?
     
  3. DigitalWarlord

    DigitalWarlord Private E-2

    Windows 7 Home Premium.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this:

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. DigitalWarlord

    DigitalWarlord Private E-2

    Here is the log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple infections.


    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot into normal Windows. If you can then continue with the below.

    READ & RUN ME FIRST. Malware Removal Guide
     
  7. DigitalWarlord

    DigitalWarlord Private E-2

    I was able to boot windows normally so I tried the cleaning procedures. I couldn't get rogue killer to finish and MG tools only went as far as making the uninstall log. These are the logs I was able to get.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Will RogueKiller run if you boot in safe boot mode? If yes, run it that way and provide a log.

    Do you recognize the below as something you installed?
    C:\Users\Skoollive2\AppData\Roaming\TradeStation Technologies\WINFDA0.exe

    Possibly related to something with gaming because it shows as a startup process registry key per the below.
    Run Hitman Pro again and allow it to make the below repairs:
    Code:
    Repairs _____________________________________________________________________
       Redirection: MpClient.dll -> c:\windows\system32\config
       Disables Windows Defender (C:\Program Files\Windows Defender)
       Redirection: MpRTP.dll -> c:\windows\system32\config
       Disables Windows Defender (C:\Program Files\Windows Defender)
       Redirection: MpSvc.dll -> c:\windows\system32\config
       Disables Windows Defender (C:\Program Files\Windows Defender)
    
    Then reboot. Run a new scan with Hitman Pro after reboot and attach the new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds