Poopack causing Black screen with cursor on startup.


Recommended Posts

Just wanted to let everyone know that within the past 2 weeks I've gotten calls from people who have installed a poopack (aka ###### pack of adware) that will break the explorer shell and cause a black screen and cursor on startup.

 

The good news is if you want to remotely connect to them, their internet is fully functional. In my case to get connected to them I have them do a control alt delete. Then have them start the Task Manger.Then have them go to file / New task, and have them type in the web address of my remote assistance software (example www.fastsupport.com) ... this allows them to still download the software and get me connected to their PC even if they can't get the explorer shell.

 

Once connected, in the Task Manager there are 2 processes, both called runonce.exe . Once you kill those the explorer shell auto launches and you get the desktop back. In one case they weren't there, and you just had to kill explorer.exe and manually launch explorer.exe again.

 

After the normal adware cleanup the computer would boot normal.

 

Just a heads up on how to get connected to clean it up.

easier 3 key salute to enter task manager (easier that ctrl alt del) as it brings you directly to the task manager, not an option screen that has a point and click option to enter the task manager.

 

ctrl shift esc

 

and that key combination is all on the left hand side of the keyboard...works on win 2000 to current.

  • Like 2

easier 3 key salute to enter task manager (easier than ctrl alt del)

 

ctrl shift esc

 

and that key combination is all on the left hand side of the keyboard...works on win 2000 to current.

 

Good to know!

There is some more info about it here. Mostly this link talks about how sourceforge is now bundling crapware on their installers. But in the post also explains the issue of this thread.

 

We all know that Sourceforge started wrapping all its hosted projects in an installer that put shovelware toolbars and the like on unsuspecting users' computers a while back.

 

I'm here to tell you it's gotten really, really bad. Today I got called into a client office with a completely unusable machine - it hung on a blank desktop, not even the wallpaper rendering, forever on user login.

 

The culprit was WSE_Taplika, installed by the SourceForge wrapper when the user downloaded and installed the Filezilla FTP client yesterday. Confirmed through logs and browser history. I took a look at this thing and it is AWFUL.

 

The process hanging the user login was a W32script in a temp folder under the user's Roaming appdata folder, by way of the user's RunOnce regkey. The actual script being run was obfuscated with octal encoding like a php script dropped on a compromised webserver, and the regkey would restore itself automatically if you deleted it, thanks to a watchdog process.

 

http://www.reddit.com/r/sysadmin/comments/2ux2uy/sourceforge_has_gotten_really_really_bad/

There is some more info about it here. Mostly this link talks about how sourceforge is now bundling crapware on their installers. But in the post also explains the issue of this thread.

 

http://www.reddit.com/r/sysadmin/comments/2ux2uy/sourceforge_has_gotten_really_really_bad/

 

Every major software distributer like source forge is bundling crap. Its sad but its true. 

There is some more info about it here. Mostly this link talks about how sourceforge is now bundling crapware on their installers. But in the post also explains the issue of this thread.

 

 

http://www.reddit.com/r/sysadmin/comments/2ux2uy/sourceforge_has_gotten_really_really_bad/

 

FileZilla customers complained to FileZilla creator about it and the forum kept going about it:

 

https://forum.filezilla-project.org/viewtopic.php?f=1&t=31967 

 

I checked the download links on their website by hovering the links and noticed the files are being hosted by Sourceforge.

 

There is no direct links that are hosted by FileZilla.. (not on my end, at least, because I can't find the clean installer.)

 

I guess I will uninstall it and find alternative FTP client.

FileZilla customers complained to FileZilla creator about it and the forum kept going about it:

 

https://forum.filezilla-project.org/viewtopic.php?f=1&t=31967 

 

I checked the download links on their website by hovering the links and noticed the files are being hosted by Sourceforge.

 

There is no direct links that are hosted by FileZilla.. (not on my end, at least, because I can't find the clean installer.)

 

I guess I will uninstall it and find alternative FTP client.

 

The worst are those "uninstallers" which try to install about 5 different apps. I had one yesterday and I had to decline about 5 offers just to get the "Uninstaller" to finish.

 

A woman called me on the phone this morning and I could have finished the sentience for her. She said ...

 

"My daughters computer came with a 30 day trial of mcafee, I uninstalled it and installed that one you put on your systems, avast." ...

 

What I wanted to tell her is "And now your system has a bunch of popups" ..

 

She said ... "Now my system has a bunch of stuff popping up all over the place"

 

... Yep, she googled for it... and hit a poo pack.

The worst are those "uninstallers" which try to install about 5 different apps. I had one yesterday and I had to decline about 5 offers just to get the "Uninstaller" to finish.

 

 

Creator should have added donate button on their software.. Pretty simple.  And remove sourceforge hosting links from their website. So creator can gain the trust back.

 

It's very lame to add options to the installer and decline apps during the installation...  It's so 90's.

 

I have seen other softwares that have donate buttons these days now. Which is good. Paint.net, for example.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Uhm, that's every business ever, though. It doesn't matter if a bajillion users are using it. As long as it's not making bank, it's probably headed for the graveyard.
    • Yeah Patchou was an active member here, good ol' times indeed.
    • Samsung is the new Google... they don't care if millions of people are using it.
    • Still no word on Tides of Annihilation...... so weird that it wasn't shown at the big Game Fest. Guess I'll put it in the bin like Judas and Squadron 42.
    • Samsung is shutting down yet another app used by millions by David Uzondu Samsung has announced that it is shutting down Samsung Max, its VPN service used by more than 50 million people, effective today. Samsung Max VPN, if you don't know, was an Android app born on February 23, 2018, out of the ashes of Opera Max, a very popular data-saving VPN that Opera had discontinued the previous year. Samsung bought the discontinued service, rebranded it, and added a native Samsung UI to fit the Galaxy ecosystem. The app could do things like compress images, help you manage background data on a per-app basis, reduce video data consumption, shrink music files, optimize webpages, block advertisement trackers in incognito mode, and encrypt your internet traffic on public Wi-Fi networks. Image via SammyGuru If you open the app now, you'd be greeted by a shutdown banner warning that all VPN, data saving, and privacy services stopped functioning on June 15, 2026. The creators failed to provide a reason for the shutdown, instead publishing a farewell note that read: "Thank you for being with us over the years. Your support and activity truly meant a lot to us and helped shape this app into what it became." This same message appears on the Google Play Store listing for the app as well. Max VPN is the latest service from Samsung to join the list of discontinued applications from the company. Just two months ago, the Korean tech giant announced that it is completely shutting down Samsung Messages, forcing millions of users to migrate to Google Messages by next month. The only devices that the shutdown won't affect are older smartphones running Android 11 or lower. Some of the features of Google Messages that Samsung hopes will entice users include AI-powered scam detection to block suspicious links, integrated Gemini AI tools to generate quick replies, custom chat bubbles, and universal RCS compatibility for sharing high-quality media with iOS users. The platform also offers seamless syncing across tablets and smartwatches. In addition to that, users gain access to message scheduling, smart classification, and automated category sorting. Via: SammyGuru
  • Recent Achievements

    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      499
    2. 2
      +Edouard
      195
    3. 3
      PsYcHoKiLLa
      125
    4. 4
      Steven P.
      85
    5. 5
      neufuse
      73
  • Tell a friend

    Love Neowin? Tell a friend!