Has anyone seen this?

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
User avatar
striker8000
Posts: 881
Joined: Tue Mar 02, 2004 5:28 pm
Location: lost in time

Has anyone seen this?

Post by striker8000 »

I've had 3 calls in the last two days for this problem:
windows appears to boot normally until just before the login page, then
the mouse cursor appears and nothing else (blank screen with a cursor that moves)
no other options, ctrl-alt-del doesn't work

safe mode, last known good, system restore, and hp's system recovery do not work (they stop at the same spot)

only solution I have found is to install windows to a different folder (to prevent deletion of important files) and configure the new install for long term use.
the repair utility on Vista's dvd doesn't fix the problem, either

the machines were:
hp desktop, winxp
hp desktop, vista, possibly caused by a bad memory card, replaced the card then had to tackle this problem with vista
dell laptop, winxp
still folding away, haven't been on as much lately
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

striker8000 wrote:I've had 3 calls in the last two days for this problem:
windows appears to boot normally until just before the login page, then
the mouse cursor appears and nothing else (blank screen with a cursor that moves)
no other options, ctrl-alt-del doesn't work

safe mode, last known good, system restore, and hp's system recovery do not work (they stop at the same spot)

only solution I have found is to install windows to a different folder (to prevent deletion of important files) and configure the new install for long term use.
the repair utility on Vista's dvd doesn't fix the problem, either

the machines were:
hp desktop, winxp
hp desktop, vista, possibly caused by a bad memory card, replaced the card then had to tackle this problem with vista
dell laptop, winxp
I've had nearly 20 laptops in this week with this problem... I'm not exactly which spyware/virus or malware is causing it but it is something. There is no fix, I've tried looking through files when slaving the drive, repair installs, chkdsk options etc... nothing but backing up data and reimage/format and reinstall the system.

Here is a list off a laptop this morning that I got in thats doing the same thing... at this point hard to say which is causing it even after I remove this crap by slaving the drive.

Image
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Perform manual restoration of restore points from the command line, to a date prior to infection. May take several tries to find the date prior to it getting hosed.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

YeOldeStonecat wrote:Perform manual restoration of restore points from the command line, to a date prior to infection. May take several tries to find the date prior to it getting hosed.
I tried that on two different latitude models yesterday..no go. This is even after slaving the drives and removing what I could with superantispyware. I've not found a solution besides backing up data and reloading them.
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Sava700 wrote:I tried that on two different latitude models yesterday..no go. This is even after slaving the drives and removing what I could with superantispyware. I've not found a solution besides backing up data and reloading them.
Huh, worked for me, ident symptoms.....after slave scanned with Eset though. I'm guessing it's the latest variant, as I didnt' get to see the splash screen from the rogue running...probably that new Antivirus 360 I stumbled across earlier this week.

Over the past several months...wow are they getting more and more time consuming. By next spring I'll just fix things with a giant magnet.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

YeOldeStonecat wrote:Huh, worked for me, ident symptoms.....after slave scanned with Eset though. I'm guessing it's the latest variant, as I didnt' get to see the splash screen from the rogue running...probably that new Antivirus 360 I stumbled across earlier this week.

Over the past several months...wow are they getting more and more time consuming. By next spring I'll just fix things with a giant magnet.
:rotfl: yeah I like the magnet idea...but yeah hasn't worked thus far. I'll try the next one I get cause I'm sure I'll get another today.
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Another thing I forgot to mention......
First..what it comes down to, is how much time you want to invest in this...weigh the time/effort invested in cleaning/repairing, versus time to backup the data and do a wipe/fresh install.

...anyways..a little over a month ago, one new variant I stumbled across was loading after putting some stub files in the print spooler directory, as well as system32\dllcache directory. May be able to browse those via command prompt, or if slaved from another drive. Proceed with caution...certain files there are legit.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Dave's World has a rig on the service bench right now exhibiting similar behavior....it is able to sometimes get to safe mode...but it keeps reloading, over and over again, explorer.exe. If you do get to safe mode....it will reload the logon for you..with that common "You are in safe mode" warning.

It made malwarebytes blue screen in safe mode on one pass.

This system had a program on it called "Big Fix"...which is a driver/system updater program, freebie I think, been around a long time. Similar to incredimail.....while not directly spyware itself, the programs come with some adware which seems to always eventually snowball the system over time with more junk. This rig has a new Vundu variant which isn't exactly identified yet...just being called "Vundu.Rogue"...by Spybot and MB.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Something else odd with this new variant.....
As being able to log into safe mode started working more....in addition to that constant "you are working in safe mode..." greeting from explorer constantly reloading, the "log in screen" in safe mode appears in full color and resolution. Normally this is crippled in safe mode 640 x 460 low color resolution. Several reboots in a row after hittin the F8 during bootup and selecting safe mode...we were greeting with full color 1280x1024 login screen on this PC...once you'd log in..the desktop would snap back into safe mode.

:wth:
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
TonyT
SG VIP
Posts: 10356
Joined: Fri Jan 28, 2000 12:00 am
Location: Fairfax, VA

Post by TonyT »

Mount the disk on a Linux box or boot from a live linux cd and delete:
docs & settings/user/local settings/tif delete the dir itself
docs & settings/user/temp/ all files
windows/temp/ all files

Check these dirs for suspicious programs:
docs & settings/all users/start menu/programs/startup
docs & settings/user/start menu/programs/startup

There are even live linux distros that have a registry editor and you can remove unwanted pointers to malware, such as in this hive: hklm/software/microsoft/windows/current version/run
http://www.extremetech.com/article2/0,1 ... 485,00.asp

Worst case is one could just create a .CMD file that deletes ALL values in the common startup locations in the registry and using a linux live cd, copy the cmd file to the root of the boot partition and place a shortcut to it in the all users start menu/startup folder, boot the comp in safe mode and after login the cmd file will execute. Reboot again and should be able to get to Windows nicely! Might even be able to run the cmd file from the windows recovery console.
No one has any right to force data on you
and command you to believe it or else.
If it is not true for you, it isn't true.

LRH
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

How'd ya make out Striker? Got the one we had finished up this morning.
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
TonyT
SG VIP
Posts: 10356
Joined: Fri Jan 28, 2000 12:00 am
Location: Fairfax, VA

Post by TonyT »

I had a variant of this malware today...formatting the disk as I type!
Booted once into safe mode successfully, removed a bunch of crap, removed rootkits, was in an endless loop of reboots & bsods for next 3 hrs.
Couldn't even get a decent restore point via the recovery console! Bye bye old xp, hello new xp.
No one has any right to force data on you
and command you to believe it or else.
If it is not true for you, it isn't true.

LRH
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

I talked to the helpdesk peeps the other day and they said they have been taking in alot of pc's with viruses lately. :wth:
User avatar
striker8000
Posts: 881
Joined: Tue Mar 02, 2004 5:28 pm
Location: lost in time

Post by striker8000 »

it's nice to know that I'm not the only one seeing this, the odd part is how different some of the experiences listed are.

it was a quick spike, got a bunch of them all at once, haven't seen any since
still folding away, haven't been on as much lately
Post Reply