Boots to black screen with curser...

Discussion in 'Malware Help (A Specialist Will Reply)' started by hunters, Oct 14, 2014.

  1. hunters

    hunters Private E-2

    The computer will boot up just fine to the user screen, but once I put in the pw to any account, I just get a black screen with the curser and nothing else. I can boot into safe mode just fine. Thank you for any help you can provide...

    All scans had to be run in safe mode...
    Malwarebytes crashes during update and during scan and never got through a scan to complete.
     

    Attached Files:

  2. hunters

    hunters Private E-2

    FYI, I believe it is possibly malware because when this first occurred, I was able to run MWB in safe mode and it detected a bunch of stuff which I quarantined
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below using Revo Uninstaller

    • Browser System Enahncer
    • deal2dealit
    • Shopop
    • Viewpoint Media Player



    Re run Hitman Pro and allow it to remove what it finds.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Internet Name Service (C:\Windows\system32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Windows Internet Name Service (C:\Windows\system32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe) -> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Windows Internet Name Service (C:\Windows\system32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe) -> Found
    • [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2058723574-2682080530-1496112647-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVf-> Found
    • [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2058723574-2682080530-1496112647-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://feed.helperbar.com/?p=mKO_AwFzXIpYRbPGr6Jy1Ks2e111hOmaVHQAxQHSlVf-> Found
    • [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\PROGRA~3\BROWSE~1\BROWSE~2.DLL -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Re run TDSSKiller )just a scan) and attach the newest log please.


    Now do this so I can see what remains -

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. hunters

    hunters Private E-2

    Got help elsewhere, thanks anyway for responding. Can I close this post?
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where at? :confused And cross posting is frowned upon, just in case this is what happened. :(
     
  6. hunters

    hunters Private E-2

    Not cross posting, time became a factor and I needed to get help elsewhere.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds