BleepingComputer.com: blackscreen on boot - unhide.exe

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

blackscreen on boot - unhide.exe

#1 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 09 May 2011 - 03:22 PM

I received an error on one of our users aptop this morning and upon follwing the Windows Recovery in Bleeping Computer. I keep getting the pc to reboot to the blackscreen over and over. How can I get past this feature and boot into the Administrator profile?

#2 User is offline   dc3 

  • Recalcitrant
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 9,478
  • Joined: 04-March 05
  • Gender:Not Telling

Posted 09 May 2011 - 08:36 PM

Can you boot into Safe Mode?

It would help if you were to post the make and model of this computer.

It would also help if you were to post the exact error message.

#3 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 10 May 2011 - 04:06 AM

When do you see this black screen? Are you able to tap F8 on startup and see the Advanced Boot Options menu, do you still see the XP splash screen?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#4 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 10 May 2011 - 11:53 AM

I recently ran into a issue after running the Unhide.exe from a laptop and now can't access my safemode or local login. Comes back and says it can't find any hard disk drives installed. How can a simple Unhide.exe feature casue such trouble?

This post has been edited by hamluis: 10 May 2011 - 04:58 PM
Reason for edit: Moved from XP to Am I Infected.


#5 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,447
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 10 May 2011 - 04:57 PM

Well...there's always the possibility...that you had problems before running the named application...and that running it just complicated the basic issues.

Since the unhide.exe is a tool designed to be used in connection with malware issues...I'd say that the possibility exists that malware is your problem.

I will move this to the Am I Infected forum, where a better assessment than mine...can be made.

Louis

#6 User is offline   etavares 

  • Bleepin' Remover
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 10,743
  • Joined: 16-August 08
  • Gender:Male

Posted 10 May 2011 - 05:21 PM

Hello and welcome to Bleeping Computer

My name is etavares and I will be working with you to fix your computer.

Please take note:

  • If you have since resolved the original problem you were having, we would appreciate you letting us know.
  • Please tell us if you have your original Windows CD/DVD available.
  • If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information.
  • Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting. If you will be unable to respond (e.g. vacation, travel, etc.), please let me know ahead of time.
  • Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.



This sounds like it may be a MBR rootkit that was partially removed. It could also be hardware failure. In addition to the questions above, I have a lot of others we need to get started:

Do you get any beeps when you boot? If so, what is the pattern (here's some examples

What virus did you have to remove that caused you to run unhide? In addition to letting me know if you have a windows CD handy, please also let me know if you have a non-infected computer you can use and a USB flash drive we can play with to gain access to the drive?

Also, is this a dual boot system or does it only have one operating system on it? Which OS is it? Windows XP? Vista? 7? Are you running any disk encryption?

Thanks!
-etavares

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Posted Image
Unified Network of Instructors and Trusted Eliminators


#7 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 10 May 2011 - 11:58 PM

adminoem2111, I merged both topics as they discuss the same problem. Please do not start any other topics, instead reply in this one if you still need help.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#8 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 11 May 2011 - 08:11 AM

In regards to all the forums, it's a HP Compaq nx7400, and was brought to me with a Windows Recovery error message. I went thru and found a document from bleeping computer and followed it to a tee, when installing the Unhide.exe application, this is when I noticed the pc was stalled at one particualr screen and restarted it. Probley what started the whole issue of not beign able to get back into the laptop from either the local login nor the safe mode, I was completly locked out. So that's the point I desided to look for a way to restore my registory and find a back way into the laptop. I've since restored the laptop from a recovery backup, but running into a lsass.exe error now and wont allow me to get logged on either.

#9 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 11 May 2011 - 08:42 AM

What kind of backup did you use to restore?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#10 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 11 May 2011 - 08:59 AM

My laptop had a restored drive that was setup by HP, when booting to the safe mode, it prompt me if I want to restore from backup drive. It's a partition on the drive that's setup especially for just these kind of details.

#11 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 11 May 2011 - 09:02 AM

What exactly is the lsass.exe error?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#12 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 11 May 2011 - 09:51 AM

It's an annoying popup message that won't allow you to gain access the system, locally or thru safemode, the following messages is what shows up if you have th time to read it before it reboots the pc/laptop. Very aggravating!!!!!!

"System error: Lsass.exe
When trying to update a password the return status indicates that the value provided as the current password is not correct."
Then my machine restarts and tries again, and again and again.....

#13 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 11 May 2011 - 10:38 AM

That usually happens when the LSA key is broken. Have you tried booting using the Last Known Good Configuration?

Did you do anything to the registry after restoring the backup?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#14 User is offline   adminoem2111 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 7
  • Joined: 09-May 11

Posted 11 May 2011 - 10:58 AM

Tried the Last Known Configuration and it to didn't take off. Seems that everything I tried sent the laptop into a restarting process and repeated over and over.

I had copied all the information on the hard drive off externially by hooking up the laptop hard drive to my desktop system via a CoolGear cable and copied the files off to the local network of my desktop pc. Then proceded to put the laptop harddrive back in and downloaded the latest Windows updates and removed once again and migrated the saved files from my pc back to the hard drive completing the task late yesterday. Upon rebooting this morningis when I received the error. So I've once restored the laptop from a good backup regestry devise and hopefully with any luck I'll have it this time.

Thx.

#15 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 38,999
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 11 May 2011 - 11:16 AM

Quote

So I've once restored the laptop from a good backup regestry devise and hopefully with any luck I'll have it this time.
Sorry, but I'm not sure I am following you here. You only restored the registry backup? And now still get the LSASS.exe error?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users